Sourceforge Sox Sound Exchange vulnerabilities
2 known vulnerabilities affecting sourceforge/sox_sound_exchange.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-1010004HIGHCVSS 7.5v≤ 14.4.22019-07-15
CVE-2019-1010004 [HIGH] CVE-2019-1010004: SoX - Sound eXchange 14
SoX - Sound eXchange 14.4.2 and earlier is affected by: Out-of-bounds Read. The impact is: Denial of Service. The component is: read_samples function at xa.c:219. The attack vector is: Victim must open specially crafted .xa file. NOTE: this may overlap CVE-2017-18189.
cvelistv5
CVE-2017-18189HIGHCVSS 7.5v≤ 14.4.22018-02-15
CVE-2017-18189 [HIGH] CWE-476 CVE-2017-18189: In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifyin
In the startread function in xa.c in Sound eXchange (SoX) through 14.4.2, a corrupt header specifying zero channels triggers an infinite loop with a resultant NULL pointer dereference, which may allow a remote attacker to cause a denial-of-service.
nvdosv