← Vulnerability feed

Vulnerability record · CVE-2017-9260 · published 27 July 2017

CVE-2017-9260: Surina soundtouch out-of-bounds read vulnerability

Surina · Soundtouch

The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.

5.5 CVSS 3.0 Medium EPSS 3.9% · top 10.1% CWE-125 · Out-of-bounds read
5.5CVSS 3.0 base score, v2 4.3
3.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-9260 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2018-17097Surina soundtouch double free vulnerabilityThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly…EPSS 2.8%8.8CVE-2018-17098Surina soundtouch out-of-bounds write vulnerabilityThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from siz…EPSS 2.8%8.8CVE-2018-1000223Surina soundtouch memory buffer overflow vulnerabilitysoundtouch version up to and including 2.0.0 contains a Buffer Overflow vulnerability in SoundStretch/WavFile.cpp:WavInFile::readHeaderBlock() that c…EPSS 2.4%7.5CVE-2018-14044Surina soundtouch vulnerabilityThe RateTransposer::setChannels function in RateTransposer.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause …EPSS 2.6%7.5CVE-2018-14045Surina soundtouch vulnerabilityThe FIRFilter::evaluateFilterMulti function in FIRFilter.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a …EPSS 2.6%6.5CVE-2018-17096Surina soundtouch vulnerabilityThe BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (asser…EPSS 2.3%5.5CVE-2017-9258Surina soundtouch vulnerabilityThe TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (i…EPSS 4.2%5.5CVE-2017-9259Surina soundtouch uncontrolled resource consumption vulnerabilityThe TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of se…EPSS 6.2%

Source: NIST National Vulnerability Database (record CVE-2017-9260), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.