Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown
CVE-2018-10536
Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks.
0
Attacker Value
Unknown
CVE-2018-10538
Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
0
Attacker Value
Unknown
CVE-2018-10539
Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
0
Attacker Value
Unknown
CVE-2018-10537
Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.
0
Attacker Value
Unknown
CVE-2018-7254
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file.
0
Attacker Value
Unknown
CVE-2018-7253
Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.
0
Attacker Value
Unknown
CVE-2018-6767
Disclosure Date: February 06, 2018 (last updated November 26, 2024)
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.
0
Attacker Value
Unknown
CVE-2016-10170
Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0
Attacker Value
Unknown
CVE-2016-10172
Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0
Attacker Value
Unknown
CVE-2016-10171
Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0