Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Wavpack Project

First CVE: Mar 14, 2017Active for: 9 yearsTotal CVEs: 21

Wavpack is a lightweight audio codec and compression library with a narrow product footprint but presence across multimedia applications and embedded systems that handle audio decoding. The vendor's disclosed vulnerabilities center on the core Wavpack library and reflect boundary-checking weaknesses in audio-frame parsing, specifically out-of-bounds read conditions that arise from insufficient validation of crafted input streams. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
21
Total CVEs
More Total CVEs than 79% of tracked vendors
4.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
6.1
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Wavpack Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2017
9 years ago
Most Recent CVE
Jul 19, 2022
1,466 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-7254HIGH
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a bu
Feb 19, 20187.841NOYES
CVE-2018-7253HIGH
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overw
Feb 19, 20187.826NONO
CVE-2018-6767HIGH
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly ha
Feb 6, 20187.826NONO
CVE-2018-10537HIGH
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c do
Apr 29, 20187.825NONO
CVE-2018-10536HIGH
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does n
Apr 29, 20187.825NONO
CVE-2019-11498MEDIUM
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow atta
Apr 24, 20196.523NONO
CVE-2016-10172MEDIUM
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
Mar 14, 20175.522NONO
CVE-2021-44269MEDIUM
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is to
Mar 10, 20225.521NONO
CVE-2018-19841MEDIUM
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application cra
Dec 4, 20185.521NONO
CVE-2016-10169MEDIUM
The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
Mar 14, 20175.521NONO
View all 21 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products21 CVEs
76%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local20 (95.2%)
Network1 (4.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required21 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Wavpack Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Wavpack Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Wavpack Project's Products

View all 3 CNAs →

Top CWEs