Libaacplus is a niche audio codec library whose vulnerability profile centers on a single product with exposure rooted in parser and arithmetic-handling issues, particularly improper input validation, integer overflow conditions, and reachable assertions that arise from processing untrusted audio streams. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libaacplus Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-7605HIGH aacplusenc.c in HE-AAC+ Codec (aka libaacplus) 2.0.2 has an assertion failure, which might allow remote attackers to cause a denial of service (application crash) or possibly have | Apr 9, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-7603HIGH au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a signed integer overflow, which might allow remote attackers to cause a denial of service (application crash) or possibly | Apr 9, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-7604HIGH au_channel.h in HE-AAC+ Codec (aka libaacplus) 2.0.2 has a left-shift undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) | Apr 9, 2017 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libaacplus Project.
Media articles that mention a CVE ID that affects a product developed by Libaacplus Project — matched by CVE ID, not by vendor name.