Audacityteam maintains Audacity, a widely used open-source audio-editing application whose vulnerability profile centers on memory-safety and file-handling issues including buffer overflows, link-following flaws, and search-path manipulation. The vendor's disclosures frequently acquire public exploit tooling, reflecting both the accessibility of the codebase and the appeal of local-privilege and code-execution vectors in desktop applications. Defenders tracking this vendor should prioritize updates for users in shared or untrusted environments; live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Audacityteam over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0490HIGH Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attack | Feb 10, 2009 | 9.3 | 44 | NO | YES |
CVE-2017-1000010HIGH Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution. | Jul 17, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-2541MEDIUM Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file. | Feb 7, 2018 | 5.5 | 18 | NO | NO |
CVE-2016-2540MEDIUM Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure. | Feb 7, 2018 | 5.5 | 18 | NO | NO |
CVE-2007-6061MEDIUM Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of servic | Nov 20, 2007 | 5.0 | 17 | NO | NO |
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the | Nov 30, 2020 | 3.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Audacityteam.
Media articles that mention a CVE ID that affects a product developed by Audacityteam — matched by CVE ID, not by vendor name.