WavPack is an audio codec and compression library with a focused product footprint that achieves prominence within the media processing ecosystem, where memory-safety flaws carry direct risk to any application that decodes untrusted audio streams. Its vulnerability profile concentrates around memory access violations and uninitialized-resource handling—out-of-bounds reads and writes, use of uninitialized pointers and variables—which are characteristic of low-level codec implementations and tend to acquire public exploit code. Defenders should treat WavPack library updates as relevant to media players, containerization tools, and streaming applications that embed the codec; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wavpack over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7254HIGH The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a bu | Feb 19, 2018 | 7.8 | 41 | NO | YES |
CVE-2018-7253HIGH The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overw | Feb 19, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-6767HIGH A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly ha | Feb 6, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-10537HIGH An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c do | Apr 29, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-10536HIGH An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does n | Apr 29, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-11498MEDIUM WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow atta | Apr 24, 2019 | 6.5 | 23 | NO | NO |
CVE-2016-10172MEDIUM The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | Mar 14, 2017 | 5.5 | 22 | NO | NO |
CVE-2021-44269MEDIUM An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is to | Mar 10, 2022 | 5.5 | 21 | NO | NO |
CVE-2018-19841MEDIUM The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application cra | Dec 4, 2018 | 5.5 | 21 | NO | NO |
CVE-2016-10169MEDIUM The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | Mar 14, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wavpack.
Media articles that mention a CVE ID that affects a product developed by Wavpack — matched by CVE ID, not by vendor name.