CVE detail
CVE-2020-35738 — CVE-2020-35738
Published 2020-12-28 · Modified 2026-06-17 · Vendor wavpack · Product wavpack · Source nvd
MEDIUM
severity
CVSS-derived band
0.0120
EPSS probability
exploitation probability, 30d
65.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2, which are also affected.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References