Wavpack

Vendor:

First CVE: Mar 14, 2017 · Active for 9 years

21
Total CVEs
More Total CVEs than 75% of tracked products
4.2
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 17% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Wavpack over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 14, 2017
9 years ago
Most Recent CVE
Jul 19, 2022
1,470 days ago

CVE Severity & Scoring

Wavpack21 CVEs
All CVEs353,173 CVEs
MediumHigh
Attack Vector
Local20 (95.2%)
Network1 (4.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low21 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None0 (0.0%)
Unknown0 (0.0%)
Required21 (100.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None21 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a bu
Feb 19, 20187.841NOYES
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overw
Feb 19, 20187.826NONO
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly ha
Feb 6, 20187.826NONO
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c do
Apr 29, 20187.825NONO
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does n
Apr 29, 20187.825NONO
WavpackSetConfiguration64 in pack_utils.c in libwavpack.a in WavPack through 5.1.0 has a "Conditional jump or move depends on uninitialised value" condition, which might allow atta
Apr 24, 20196.523NONO
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
Mar 14, 20175.522NONO
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is to
Mar 10, 20225.521NONO
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application cra
Dec 4, 20185.521NONO
The read_code function in read_words.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
Mar 14, 20175.521NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
4.8% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Wavpack

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.4.025.50.8%00
5.3.016.11.2%00
5.1.037.85.2%01