Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2020-11867

Disclosure Date: November 30, 2020 (last updated February 22, 2025)
Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary audio .au files located there.
Attacker Value
Unknown

CVE-2016-2540

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure.
0
Attacker Value
Unknown

CVE-2016-2541

Disclosure Date: February 07, 2018 (last updated November 26, 2024)
Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.
0
Attacker Value
Unknown

CVE-2017-1000010

Disclosure Date: July 17, 2017 (last updated November 26, 2024)
Audacity 2.1.2 through 2.3.2 is vulnerable to Dll HIjacking in the avformat-55.dll resulting arbitrary code execution.
Attacker Value
Unknown

CVE-2009-0490

Disclosure Date: February 10, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacity 1.2.6 and other versions before 1.3.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .gro file containing a long string.
0
Attacker Value
Unknown

CVE-2007-6061

Disclosure Date: November 20, 2007 (last updated October 04, 2023)
Audacity 1.3.2 creates a temporary directory with a predictable name without checking for previous existence of that directory, which allows local users to cause a denial of service (recording deadlock) by creating the directory before Audacity is run. NOTE: this issue can be leveraged to delete arbitrary files or directories via a symlink attack.
0