VYPR

PulseAudio

by Ubuntu

CVEs (3)

  • CVE-2020-16123MedDec 4, 2020
    risk 0.29cvss 4.4epss 0.00

    An Ubuntu-specific patch in PulseAudio created a race condition where the snap policy module would fail to identify a client connection from a snap as coming from a snap if SCM_CREDENTIALS were missing, allowing the snap to connect to PulseAudio without proper confinement. This…

  • CVE-2024-11586MedNov 23, 2024
    risk 0.26cvss 4.0epss 0.00

    Ubuntu's implementation of pulseaudio can be crashed by a malicious program if a bluetooth headset is connected.

  • CVE-2020-11931LowMay 15, 2020
    risk 0.21cvss 3.3epss 0.00

    An Ubuntu-specific modification to Pulseaudio to provide security mediation for Snap-packaged applications was found to have a bypass of intended access restriction for snaps which plugs any of pulseaudio, audio-playback or audio-record via unloading the pulseaudio snap policy…