The Flac Project maintains a single, widely embedded audio codec library used across media players, streaming applications, and audio processing tools throughout consumer and professional software ecosystems. Its vulnerability profile centers on classic memory-safety weaknesses—buffer overflows and resource-management issues—that recur in parsing and decompression routines, typical of native-code codec implementations. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flac Project over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6277HIGH Multiple buffer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via large (1) Metadata Block Size, | Dec 7, 2007 | 9.3 | 28 | NO | NO |
CVE-2007-6279HIGH Multiple double free vulnerabilities in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allow user-assisted remote attackers to execute arbitrary code via malformed (1) Seekt | Dec 7, 2007 | 9.3 | 26 | NO | NO |
CVE-2007-6278HIGH Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1 allows user-assisted remote attackers to force a client to download arbitrary files via the MIME-Type URL flag (-->) for the F | Dec 7, 2007 | 9.3 | 25 | NO | NO |
CVE-2007-4619HIGH Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execut | Oct 12, 2007 | 9.3 | 25 | NO | NO |
CVE-2014-9028HIGH Heap-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file. | Nov 26, 2014 | 7.5 | 23 | NO | NO |
CVE-2014-8962HIGH Stack-based buffer overflow in stream_decoder.c in libFLAC before 1.3.1 allows remote attackers to execute arbitrary code via a crafted .flac file. | Nov 26, 2014 | 7.5 | 23 | NO | NO |
CVE-2020-22219HIGH Buffer Overflow vulnerability in function bitwriter_grow_ in flac before 1.4.0 allows remote attackers to run arbitrary code via crafted input to the encoder. | Aug 22, 2023 | 7.8 | 21 | NO | NO |
CVE-2017-6888MEDIUM An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC | Apr 25, 2018 | 5.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flac Project.
Media articles that mention a CVE ID that affects a product developed by Flac Project — matched by CVE ID, not by vendor name.