PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LENGTH value of FRAME_SIZE_MAX_ALLOW sent on TCP port 9875, which triggers a p->export assertion failure in do_read; (2) a PA_PSTREAM_DESCRIPTOR_LENGTH value of 0 sent on TCP port 9875, which triggers a length assertion failure in pa_memblock_new; or (3) an empty packet on UDP port 9875, which triggers a t assertion failure in pa_sdp_parse; and allows remote authenticated users to cause a denial of service (daemon crash) via a crafted packet on TCP port 9875 that (4) triggers a maxlength assertion failure in pa_memblockq_new, (5) triggers a size assertion failure in pa_xmalloc, or (6) plays a certain sound file.
Conclusion & alert: CVE-2007-1804 is rated High Exploit Risk (84.8/100): CVSS High severity, with high exploitation likelihood (EPSS 23.98%, 96th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +8.74% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 29809 | exploit_db | edb | 2007-04-02 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-02-05 | 15.24% | 23.98% | +8.74% |
| 2 | 2025-11-19 | 14.74% | 15.24% | +0.49% |
| 3 | 2025-03-30 | — | 14.74% | — |
Full EPSS history (14 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.8 | 2.0 | HIGH |
|
10.0 | 6.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
low | CVE-2007-1804 low priority: Debian including 1 source packages (pulseaudio), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2007-1804 |
ubuntu
|
medium | CVE-2007-1804 medium priority: Ubuntu including 1 source packages (pulseaudio), 4 status rows across 4 suites (dapper, edgy, feisty, upstream): DNE 2, needs-triage 1, released 1. | https://ubuntu.com/security/CVE-2007-1804 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| pulseaudio | pulseaudio | 0.9.5 | cpe:2.3:a:pulseaudio:pulseaudio:0.9.5:*:*:*:*:*:*:* |