← Back

Sound Exchange

sound_exchange

Vendor: Sound Exchange Project • 27 CVEs

CVEs (27)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Oct 16, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a stack-based buffer overflow in the lsx_ms_adpcm_block_expand_i function of adpcm.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Oct 16, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a reachable assertion abort in the function sox_append_comment() in formats.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Oct 16, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
There is a heap-based buffer overflow in the ImaExpandS function of ima_rw.c in Sound eXchange (SoX) 14.4.2. A Crafted input will lead to a denial of service attack during conversion of an audio file.
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The wavwritehdr function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted snd file, during conversion to a wav file.
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The read_samples function in hcom.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a crafted hcom file.
2Debian
Sound Exchange Project
2Debian Linux
Sound Exchange
May 13, 2026
Jul 31, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The startread function in wav.c in Sound eXchange (SoX) 14.4.2 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted wav file.
3Debian
OracleSound Exchange Project
3Debian Linux
SolarisSound Exchange
May 6, 2026
Dec 31, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.