FLAC's vulnerability profile centers on a narrow, widely embedded audio codec library and command-line tools used across music players, media frameworks, and streaming applications. The recurring exposure stems from the parser's handling of untrusted audio data, with durable signals in memory-safety issues such as out-of-bounds buffer operations and input-validation weaknesses that are characteristic of codec implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flac over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6277HIGH Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via large (1) Metadata Block Size, | Dec 7, 2007 | 9.3 | 28 | NO | NO |
CVE-2007-6279HIGH Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seekt | Dec 7, 2007 | 9.3 | 26 | NO | NO |
CVE-2007-6278HIGH Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the F | Dec 7, 2007 | 9.3 | 25 | NO | NO |
CVE-2007-4619HIGH Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execut | Oct 12, 2007 | 9.3 | 25 | NO | NO |
CVE-2014-9028HIGH Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file. | Nov 26, 2014 | 7.5 | 23 | NO | NO |
CVE-2014-8962HIGH Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file. | Nov 26, 2014 | 7.5 | 23 | NO | NO |
CVE-2020-22219HIGH Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder. | Aug 22, 2023 | 7.8 | 21 | NO | NO |
CVE-2017-6888MEDIUM An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC | Apr 25, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flac.
Media articles that mention a CVE ID that affects a product developed by Flac — matched by CVE ID, not by vendor name.