Audacity
Vendor:
First CVE: Nov 20, 2007 · Active for 18 years
6
Total CVEs
More Total CVEs than 80% of tracked products
1.2
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Audacity over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 20, 2007
18 years ago
Most Recent CVE
Nov 30, 2020
2,062 days ago
CVE Severity & Scoring
Audacity6 CVEs
17%
50%
33%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (66.7%)
Network0 (0.0%)
Unknown2 (33.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (66.7%)
High0 (0.0%)
Unknown2 (33.3%)
User Interaction
None1 (16.7%)
Unknown2 (33.3%)
Required3 (50.0%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None3 (50.0%)
Unknown2 (33.3%)
Top CVEs
Signals from CVEs in this product scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0490HIGH Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attack | Feb 10, 2009 | 9.3 | 44 | NO | YES |
CVE-2017-1000010HIGH Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution. | Jul 17, 2017 | 7.8 | 20 | NO | NO |
CVE-2016-2541MEDIUM Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file. | Feb 7, 2018 | 5.5 | 18 | NO | NO |
CVE-2016-2540MEDIUM Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure. | Feb 7, 2018 | 5.5 | 18 | NO | NO |
CVE-2007-6061MEDIUM Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of servic | Nov 20, 2007 | 5.0 | 17 | NO | NO |
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the | Nov 30, 2020 | 3.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (6 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
16.7% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (6 CVEs).
Media Mentions
Signals from CVEs in this product scope (6 CVEs).
Top CNAs Publishing CVEs For Audacity
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.3.2 | 1 | 5.0 | 3.4% | 0 | 0 |