CVE-2023-34432
- EPSS 0.05%
- Published 10.07.2023 21:15:10
- Last modified 21.11.2024 08:07:13
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
CVE-2023-34318
- EPSS 0.04%
- Published 10.07.2023 18:15:10
- Last modified 27.06.2025 18:51:27
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
CVE-2023-32627
- EPSS 0.06%
- Published 10.07.2023 18:15:10
- Last modified 27.06.2025 18:51:27
A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
CVE-2023-26590
- EPSS 0.04%
- Published 10.07.2023 18:15:10
- Last modified 27.06.2025 18:51:27
A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
CVE-2021-33844
- EPSS 0.04%
- Published 25.08.2022 20:15:09
- Last modified 27.06.2025 18:51:27
A floating point exception (divide-by-zero) issue was discovered in SoX in functon startread() of wav.c file. An attacker with a crafted wav file, could cause an application to crash.
CVE-2021-23210
- EPSS 0.03%
- Published 25.08.2022 20:15:09
- Last modified 27.06.2025 18:51:27
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
CVE-2021-23172
- EPSS 0.04%
- Published 25.08.2022 20:15:08
- Last modified 27.06.2025 18:51:27
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function startread() in hcom.c file. The vulnerability is exploitable with a crafted hcomn file, that could cause an application to crash.
CVE-2021-23159
- EPSS 0.03%
- Published 25.08.2022 20:15:08
- Last modified 27.06.2025 18:51:27
A vulnerability was found in SoX, where a heap-buffer-overflow occurs in function lsx_read_w_buf() in formats_i.c file. The vulnerability is exploitable with a crafted file, that could cause an application to crash.
CVE-2022-31651
- EPSS 0.07%
- Published 25.05.2022 23:15:07
- Last modified 27.06.2025 18:51:27
In SoX 14.4.2, there is an assertion failure in rate_init in rate.c in libsox.a.
CVE-2022-31650
- EPSS 0.07%
- Published 25.05.2022 23:15:07
- Last modified 27.06.2025 18:51:27
In SoX 14.4.2, there is a floating-point exception in lsx_aiffstartwrite in aiff.c in libsox.a.