Vulnerabilities > Surina > Soundtouch > 2.0.0

DATE CVE VULNERABILITY TITLE RISK
2018-09-16 CVE-2018-17098 Out-of-bounds Write vulnerability in Surina Soundtouch 2.0.0
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch.
network
surina CWE-787
6.8
2018-09-16 CVE-2018-17097 Double Free vulnerability in Surina Soundtouch 2.0.0
The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch.
network
surina CWE-415
6.8
2018-09-16 CVE-2018-17096 Reachable Assertion vulnerability in Surina Soundtouch 2.0.0
The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
network
surina CWE-617
4.3
2018-08-20 CVE-2018-1000223 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Surina Soundtouch
soundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that can result in arbitrary code execution.
network
surina CWE-119
6.8
2018-07-13 CVE-2018-14045 Reachable Assertion vulnerability in Surina Soundtouch 2.0.0
The FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
network
low complexity
surina CWE-617
5.0
2018-07-13 CVE-2018-14044 Reachable Assertion vulnerability in Surina Soundtouch 2.0.0
The RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch.
network
low complexity
surina CWE-617
5.0