Wavpack
Vendor:
First CVE: Mar 14, 2017 · Active for 9 years
21
Total CVEs
More Total CVEs than 75% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Wavpack over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2017
9 years ago
Most Recent CVE
Jul 19, 2022
1,470 days ago
CVE Severity & Scoring
Wavpack21 CVEs
76%
24%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local20 (95.2%)
Network1 (4.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required21 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-7254HIGH The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a bu | Feb 19, 2018 | 7.8 | 41 | NO | YES |
CVE-2018-7253HIGH The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overw | Feb 19, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-6767HIGH A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly ha | Feb 6, 2018 | 7.8 | 26 | NO | NO |
CVE-2018-10537HIGH An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c do | Apr 29, 2018 | 7.8 | 25 | NO | NO |
CVE-2018-10536HIGH An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does n | Apr 29, 2018 | 7.8 | 25 | NO | NO |
CVE-2019-11498MEDIUM WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow atta | Apr 24, 2019 | 6.5 | 23 | NO | NO |
CVE-2016-10172MEDIUM The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | Mar 14, 2017 | 5.5 | 22 | NO | NO |
CVE-2021-44269MEDIUM An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is to | Mar 10, 2022 | 5.5 | 21 | NO | NO |
CVE-2018-19841MEDIUM The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application cra | Dec 4, 2018 | 5.5 | 21 | NO | NO |
CVE-2016-10169MEDIUM The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file. | Mar 14, 2017 | 5.5 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Wavpack
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.4.0 | 2 | 5.5 | 0.8% | 0 | 0 |
| 5.3.0 | 1 | 6.1 | 1.2% | 0 | 0 |
| 5.1.0 | 3 | 7.8 | 5.2% | 0 | 1 |