cbcvebase.
CVE-2004-0557
published 2004-08-06

CVE-2004-0557: Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary…

PriorityP352critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
25.08%
97.7th percentile
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV file header fields.

Affected

15 ranges
VendorProductVersion rangeFixed in
conectivalinux
conectivalinux
conectivalinux
debiansox< sox 12.17.4-9 (bookworm)sox 12.17.4-9 (bookworm)
gentoolinux
redhatenterprise_linux
redhatenterprise_linux_desktop
redhatfedora_core
redhatfedora_core
soxsox
soxsox
soxsox
soxsox>= 0 < 12.17.4-912.17.4-9
soxsox>= 0 < 12.17.4-912.17.4-9
soxsox>= 0 < 12.17.4-912.17.4-9

CVSS provenance

nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
osv10.0CRITICAL
vendor_debian10.0CRITICAL
vendor_redhat10.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.