Pulseaudio
Vendor:
First CVE: Apr 2, 2007 · Active for 19 years
8
Total CVEs
Bottom 1%
1.1
Avg CVEs / Year
Bottom 1%
5.7
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pulseaudio over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 2, 2007
19 years ago
Most Recent CVE
Nov 23, 2024
611 days ago
CVE Severity & Scoring
Pulseaudio8 CVEs
25%
38%
38%
All CVEs352,785 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local3 (37.5%)
Network0 (0.0%)
Unknown5 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (25.0%)
High1 (12.5%)
Unknown5 (62.5%)
User Interaction
None2 (25.0%)
Unknown5 (62.5%)
Required1 (12.5%)
Privileges Required
Low2 (25.0%)
High1 (12.5%)
None0 (0.0%)
Unknown5 (62.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1894HIGH Race condition in PulseAudio 0.9.9, 0.9.10, and 0.9.14 allows local users to gain privileges via vectors involving creation of a hard link, related to the application setting LD_BI | Jul 17, 2009 | 7.2 | 32 | NO | YES |
CVE-2007-1804HIGH PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, whi | Apr 2, 2007 | 7.8 | 32 | NO | YES |
CVE-2008-0008HIGH The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when atte | Jan 29, 2008 | 7.2 | 22 | NO | NO |
CVE-2020-15710MEDIUM Potential double free in Bluez 5 module of PulseAudio could allow a local attacker to leak memory or crash the program. The modargs variable may be freed twice in the fail conditio | Nov 19, 2020 | 6.1 | 20 | NO | NO |
CVE-2009-1299MEDIUM The pa_make_secure_dir function in core-util.c in PulseAudio 0.9.10 and 0.9.19 allows local users to change the ownership and permissions of arbitrary files via a symlink attack on | Mar 18, 2010 | 6.9 | 18 | NO | NO |
CVE-2024-11586MEDIUM Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected. | Nov 23, 2024 | 4.0 | 13 | NO | NO |
An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which | May 15, 2020 | 3.3 | 12 | NO | NO |
The pa_rtp_recv function in modules/rtp/rtp.c in the module-rtp-recv module in PulseAudio 5.0 and earlier allows remote attackers to cause a denial of service (assertion failure an | Jun 11, 2014 | 2.9 | 12 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
25.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Pulseaudio
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.0 | 1 | 2.9 | 1.5% | 0 | 0 |
| 4.0 | 1 | 2.9 | 1.5% | 0 | 0 |
| 3.0 | 1 | 2.9 | 1.5% | 0 | 0 |
| 2.1 | 1 | 2.9 | 1.5% | 0 | 0 |
| 2.0 | 1 | 2.9 | 1.5% | 0 | 0 |
| 1.99.2 | 1 | 2.9 | 1.5% | 0 | 0 |
| 1.99.1 | 1 | 2.9 | 1.5% | 0 | 0 |
| 1.1 | 1 | 2.9 | 1.5% | 0 | 0 |
| 1.0 | 1 | 2.9 | 1.5% | 0 | 0 |
| 1\ | 1 | 6.1 | 0.3% | 0 | 0 |
| 0.9.9 | 1 | 7.2 | 0.7% | 0 | 1 |
| 0.9.8 | 1 | 7.2 | 0.6% | 0 | 0 |
| 0.9.6 | 1 | 7.2 | 0.6% | 0 | 0 |
| 0.9.5 | 1 | 7.8 | 7.4% | 0 | 1 |
| 0.9.19 | 1 | 6.9 | 0.3% | 0 | 0 |
| 0.9.14 | 1 | 7.2 | 0.7% | 0 | 1 |
| 0.9.10 | 2 | 7.0 | 0.5% | 0 | 1 |