The Fdkaac Project maintains a specialized audio codec library widely embedded in media playback and transcoding infrastructure, where its narrow product scope belies significant downstream exposure across consumer and enterprise applications. Its observed vulnerability signal centers on memory-safety issues, particularly out-of-bounds writes and incorrect comparison logic in codec parsing, reflecting the low-level buffer manipulation inherent to audio decoding. Current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fdkaac Project over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37781HIGH fdkaac v1.0.3 was discovered to contain a heap buffer overflow via __interceptor_memcpy.part.46 at /sanitizer_common/sanitizer_common_interceptors.inc. | Aug 16, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-36148MEDIUM fdkaac commit 53fe239 was discovered to contain a floating point exception (FPE) via wav_open at /src/wav_reader.c. | Aug 16, 2022 | 5.5 | 20 | NO | NO |
CVE-2023-34824MEDIUM fdkaac before 1.0.5 was discovered to contain a heap buffer overflow in caf_info function in caf_reader.c. | Jun 14, 2023 | 5.5 | 17 | NO | NO |
CVE-2023-34823MEDIUM fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c. | Jun 14, 2023 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fdkaac Project.
Media articles that mention a CVE ID that affects a product developed by Fdkaac Project — matched by CVE ID, not by vendor name.