Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2018-10536

Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier. The WAV parser component contains a vulnerability that allows writing to memory because ParseRiffHeaderConfig in riff.c does not reject multiple format chunks.
0
Attacker Value
Unknown

CVE-2018-10538

Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier for WAV input. Out-of-bounds writes can occur because ParseRiffHeaderConfig in riff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
0
Attacker Value
Unknown

CVE-2018-10539

Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier for DSDiff input. Out-of-bounds writes can occur because ParseDsdiffHeaderConfig in dsdiff.c does not validate the sizes of unknown chunks before attempting memory allocation, related to a lack of integer-overflow protection within a bytes_to_copy calculation and subsequent malloc call, leading to insufficient memory allocation.
0
Attacker Value
Unknown

CVE-2018-10537

Disclosure Date: April 29, 2018 (last updated November 08, 2023)
An issue was discovered in WavPack 5.1.0 and earlier. The W64 parser component contains a vulnerability that allows writing to memory because ParseWave64HeaderConfig in wave64.c does not reject multiple format chunks.
0
Attacker Value
Unknown

CVE-2018-7254

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The ParseCaffHeaderConfig function of the cli/caff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (global buffer over-read), or possibly trigger a buffer overflow or incorrect memory allocation, via a maliciously crafted CAF file.
0
Attacker Value
Unknown

CVE-2018-7253

Disclosure Date: February 19, 2018 (last updated November 26, 2024)
The ParseDsdiffHeaderConfig function of the cli/dsdiff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service (heap-based buffer over-read) or possibly overwrite the heap via a maliciously crafted DSDIFF file.
0
Attacker Value
Unknown

CVE-2018-6767

Disclosure Date: February 06, 2018 (last updated November 26, 2024)
A stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause a denial-of-service attack or possibly have unspecified other impact via a maliciously crafted RF64 file.
0
Attacker Value
Unknown

CVE-2016-10170

Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The WriteCaffHeader function in cli/caff.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0
Attacker Value
Unknown

CVE-2016-10172

Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0
Attacker Value
Unknown

CVE-2016-10171

Disclosure Date: March 14, 2017 (last updated November 26, 2024)
The unreorder_channels function in cli/wvunpack.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.
0