Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mackron

First CVE: Jun 25, 2021Active for: 5 yearsTotal CVEs: 6

Mackron develops a focused set of lightweight audio and data-processing libraries—most notably miniaudio and dr_libs—that are widely embedded in games, media applications, and embedded systems despite their small product count. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses including heap-based buffer overflows, classic buffer overflows, double frees, and improper null termination that are characteristic of C-based audio and parsing code exposed to untrusted input. Defenders should prioritize inventory of products that bundle these libraries and apply updates promptly, as supply-chain exposure can be broad; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
6
Total CVEs
More Total CVEs than 86% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mackron over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 25, 2021
5 years ago
Most Recent CVE
Mar 17, 2026
129 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (6 CVEs).

6 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-34184CRITICAL
Miniaudio 0.10.35 has a Double free vulnerability that could cause a buffer overflow in ma_default_vfs_close__stdio in miniaudio.h.
Jun 25, 20219.830NONO
CVE-2026-29022HIGH
dr_libs dr_wav.h version 0.14.4 and earlier (fixed in commit 8a7258c) contain a heap buffer overflow vulnerability in the drwav__read_smpl_to_metadata_obj() function of dr_wav.h th
Mar 3, 20267.829NONO
CVE-2024-41147CRITICAL
An out-of-bounds write vulnerability exists in the ma_dr_flac__decode_samples__lpc functionality of Miniaudio miniaudio v0.11.21. A specially crafted .flac file can lead to memory
Mar 4, 20259.829NONO
CVE-2026-32836MEDIUM
dr_libs dr_flac.h version 0.13.3 and earlier (fixed in commits fefced4, 4f5a4cd, and 663239a) contain an uncontrolled memory allocation vulnerability in drflac__read_and_decode_met
Mar 17, 20266.224NONO
CVE-2026-32837MEDIUM
miniaudio version 0.11.25 and earlier (fixed in commits 1df46ae and 1df46ae) contain a heap out-of-bounds read vulnerability in the WAV BEXT metadata parser that allows attackers t
Mar 17, 20265.522NONO
CVE-2021-34185HIGH
Miniaudio 0.10.35 has an integer-based buffer overflow caused by an out-of-bounds left shift in drwav_bytes_to_u32 in miniaudio.h
Jun 25, 20217.822NONO
View all 6 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products6 CVEs
33%
33%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (66.7%)
Network2 (33.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (66.7%)
Unknown0 (0.0%)
Required2 (33.3%)
Privileges Required
Low1 (16.7%)
High0 (0.0%)
None5 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (6 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mackron.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mackron — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mackron's Products

View all 3 CNAs →

Top CWEs