CVE-2016-10172: Wavpack Project Wavpack

Medium severity, CVSS 5.5. EPSS: 2.1% chance of exploitation in the next 30 days.

The read_new_config_info function in open_utils.c in Wavpack before 5.1.0 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WV file.

Affected products

Published 2017-03-14. Last modified 2026-06-17.