AubioCVEs & Vulnerabilities

9 CVEs affecting Aubio products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

aubio 9
CVE-2018-19802HIGH

aubio v0.4.0 to v0.4.8 has a new_aubio_onset NULL pointer dereference.

7 Jun 2019
7.5
CVSS
CVE-2018-19801HIGH

aubio v0.4.0 to v0.4.8 has a NULL pointer dereference in new_aubio_filterbank via invalid n_filters.

7 Jun 2019
7.5
CVSS
CVE-2018-19800CRITICAL

aubio v0.4.0 to v0.4.8 has a Buffer Overflow in new_aubio_tempo.

7 Jun 2019
9.8
CVSS
CVE-2018-14523HIGH

An issue was discovered in aubio 0.4.6. A buffer over-read can occur in new_aubio_pitchyinfft in pitch/pitchyinfft.c, as demonstrated by aubionotes.

23 Jul 2018
8.8
CVSS
CVE-2018-14522HIGH

An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_pitch_set_unit in pitch/pitch.c, as demonstrated by aubionotes.

23 Jul 2018
8.8
CVSS
CVE-2018-14521HIGH

An issue was discovered in aubio 0.4.6. A SEGV signal can occur in aubio_source_avcodec_readframe in io/source_avcodec.c, as demonstrated by aubiomfcc.

23 Jul 2018
8.8
CVSS
CVE-2017-17555MEDIUM

The swri_audio_convert function in audioconvert.c in FFmpeg libswresample through 3.0.101, as used in FFmpeg 3.4.1, aubio 0.4.6, and other products, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted audio file.

12 Dec 2017
6.5
CVSS
CVE-2017-17554MEDIUM

A NULL pointer dereference (DoS) Vulnerability was found in the function aubio_source_avcodec_readframe in io/source_avcodec.c of aubio 0.4.6, which may lead to DoS when playing a crafted audio file.

12 Dec 2017
5.5
CVSS
CVE-2017-17054MEDIUM

In aubio 0.4.6, a divide-by-zero error exists in the function new_aubio_source_wavread() in source_wavread.c, which may lead to DoS when playing a crafted audio file.

29 Nov 2017
5.5
CVSS
← PrevPage 1 / 1Next →