Flawfinder version 2.0.10, (C) 2001-2019 David A. Wheeler. Number of rules (primarily dangerous function names) in C/C++ ruleset: 223 Examining data/sndobj-2.6.7+ds1/include/asio.h Examining data/sndobj-2.6.7+ds1/include/asiodrivers.h Examining data/sndobj-2.6.7+ds1/include/asiodrvr.h Examining data/sndobj-2.6.7+ds1/include/asiolist.h Examining data/sndobj-2.6.7+ds1/include/asiosys.h Examining data/sndobj-2.6.7+ds1/include/combase.h Examining data/sndobj-2.6.7+ds1/include/ginclude.h Examining data/sndobj-2.6.7+ds1/include/iasiodrv.h Examining data/sndobj-2.6.7+ds1/include/iasiothiscallresolver.h Examining data/sndobj-2.6.7+ds1/include/ladspa.h Examining data/sndobj-2.6.7+ds1/include/rfftw/config.h Examining data/sndobj-2.6.7+ds1/include/rfftw/f77_func.h Examining data/sndobj-2.6.7+ds1/include/rfftw/fftw-int.h Examining data/sndobj-2.6.7+ds1/include/rfftw/fftw.h Examining data/sndobj-2.6.7+ds1/include/rfftw/rfftw.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ADSR.h Examining data/sndobj-2.6.7+ds1/include/SndObj/AdSyn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Allpass.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Ap.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Balance.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Bend.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ButtBP.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ButtBR.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ButtHP.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ButtLP.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Buzz.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Comb.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Convol.h Examining data/sndobj-2.6.7+ds1/include/SndObj/DelayLine.h Examining data/sndobj-2.6.7+ds1/include/SndObj/EnvTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/FastOsc.h Examining data/sndobj-2.6.7+ds1/include/SndObj/FFT.h Examining data/sndobj-2.6.7+ds1/include/SndObj/FFT_alt.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Filter.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Fir.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Gain.h Examining data/sndobj-2.6.7+ds1/include/SndObj/HammingTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/HarmTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Hilb.h Examining data/sndobj-2.6.7+ds1/include/SndObj/HiPass.h Examining data/sndobj-2.6.7+ds1/include/SndObj/IADSR.h Examining data/sndobj-2.6.7+ds1/include/SndObj/IFAdd.h Examining data/sndobj-2.6.7+ds1/include/SndObj/IFFT.h Examining data/sndobj-2.6.7+ds1/include/SndObj/IFFT_alt.h Examining data/sndobj-2.6.7+ds1/include/SndObj/IFGram.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ImpulseTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Interp.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Lookup.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Lookupi.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Loop.h Examining data/sndobj-2.6.7+ds1/include/SndObj/LoPassTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/LowPass.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Lp.h Examining data/sndobj-2.6.7+ds1/include/SndObj/MidiIn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/MidiMap.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Mix.h Examining data/sndobj-2.6.7+ds1/include/SndObj/NoteTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Osc.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Osci.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Oscil.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Oscili.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Oscilt.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Pan.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Phase.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PhOscili.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Pitch.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PlnTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Pluck.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Ptrack.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVA.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVBlur.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVEnvTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVFilter.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVMask.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVMix.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVMorph.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVRead.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVS.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/PVTransp.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Rand.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Randh.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Randi.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Reson.h Examining data/sndobj-2.6.7+ds1/include/SndObj/ReSyn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Ring.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SinAnal.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SinSyn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndASIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndBuffer.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndCoreAudio.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndFIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndIn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndJackIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndMidi.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndMidiIn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndObj.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndPVOCEX.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndRead.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndRTIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndRTThread.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndSinIO.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndThread.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndWave.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SndWaveX.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecCart.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecCombine.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecEnvTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecIn.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecInterp.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecMult.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecPolar.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecSplit.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecThresh.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SpecVoc.h Examining data/sndobj-2.6.7+ds1/include/SndObj/StringFlt.h Examining data/sndobj-2.6.7+ds1/include/SndObj/SyncGrain.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Table.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Tap.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Tapi.h Examining data/sndobj-2.6.7+ds1/include/SndObj/TpTz.h Examining data/sndobj-2.6.7+ds1/include/SndObj/TrisegTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/Unit.h Examining data/sndobj-2.6.7+ds1/include/SndObj/UsrDefTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/UsrHarmTable.h Examining data/sndobj-2.6.7+ds1/include/SndObj/VDelay.h Examining data/sndobj-2.6.7+ds1/src/ADSR.cpp Examining data/sndobj-2.6.7+ds1/src/ADSR.h Examining data/sndobj-2.6.7+ds1/src/AdSyn.h Examining data/sndobj-2.6.7+ds1/src/Allpass.cpp Examining data/sndobj-2.6.7+ds1/src/Allpass.h Examining data/sndobj-2.6.7+ds1/src/Ap.cpp Examining data/sndobj-2.6.7+ds1/src/Ap.h Examining data/sndobj-2.6.7+ds1/src/asio/asio.cpp Examining data/sndobj-2.6.7+ds1/src/asio/asio.h Examining data/sndobj-2.6.7+ds1/src/asio/ASIOConvertSamples.cpp Examining data/sndobj-2.6.7+ds1/src/asio/ASIOConvertSamples.h Examining data/sndobj-2.6.7+ds1/src/asio/asiodrivers.cpp Examining data/sndobj-2.6.7+ds1/src/asio/asiodrivers.h Examining data/sndobj-2.6.7+ds1/src/asio/asiodrvr.h Examining data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp Examining data/sndobj-2.6.7+ds1/src/asio/asiolist.h Examining data/sndobj-2.6.7+ds1/src/asio/asiosys.h Examining data/sndobj-2.6.7+ds1/src/asio/combase.h Examining data/sndobj-2.6.7+ds1/src/asio/ginclude.h Examining data/sndobj-2.6.7+ds1/src/asio/iasiodrv.h Examining data/sndobj-2.6.7+ds1/src/asio/iasiothiscallresolver.cpp Examining data/sndobj-2.6.7+ds1/src/asio/iasiothiscallresolver.h Examining data/sndobj-2.6.7+ds1/src/AudioDefs.h Examining data/sndobj-2.6.7+ds1/src/Balance.cpp Examining data/sndobj-2.6.7+ds1/src/Balance.h Examining data/sndobj-2.6.7+ds1/src/Bend.cpp Examining data/sndobj-2.6.7+ds1/src/Bend.h Examining data/sndobj-2.6.7+ds1/src/ButtBP.cpp Examining data/sndobj-2.6.7+ds1/src/ButtBP.h Examining data/sndobj-2.6.7+ds1/src/ButtBR.cpp Examining data/sndobj-2.6.7+ds1/src/ButtBR.h Examining data/sndobj-2.6.7+ds1/src/ButtHP.cpp Examining data/sndobj-2.6.7+ds1/src/ButtHP.h Examining data/sndobj-2.6.7+ds1/src/ButtLP.cpp Examining data/sndobj-2.6.7+ds1/src/ButtLP.h Examining data/sndobj-2.6.7+ds1/src/Buzz.cpp Examining data/sndobj-2.6.7+ds1/src/Buzz.h Examining data/sndobj-2.6.7+ds1/src/Comb.cpp Examining data/sndobj-2.6.7+ds1/src/Comb.h Examining data/sndobj-2.6.7+ds1/src/Convol.cpp Examining data/sndobj-2.6.7+ds1/src/Convol.h Examining data/sndobj-2.6.7+ds1/src/DelayLine.cpp Examining data/sndobj-2.6.7+ds1/src/DelayLine.h Examining data/sndobj-2.6.7+ds1/src/EnvTable.cpp Examining data/sndobj-2.6.7+ds1/src/EnvTable.h Examining data/sndobj-2.6.7+ds1/src/examples/blurring.cpp Examining data/sndobj-2.6.7+ds1/src/examples/cvoc.cpp Examining data/sndobj-2.6.7+ds1/src/examples/denoiser.cpp Examining data/sndobj-2.6.7+ds1/src/examples/example1.cpp Examining data/sndobj-2.6.7+ds1/src/examples/example2.cpp Examining data/sndobj-2.6.7+ds1/src/examples/example3.cpp Examining data/sndobj-2.6.7+ds1/src/examples/extract.cpp Examining data/sndobj-2.6.7+ds1/src/examples/fir.cpp Examining data/sndobj-2.6.7+ds1/src/examples/harmonise.cpp Examining data/sndobj-2.6.7+ds1/src/examples/jack_schroeder.cpp Examining data/sndobj-2.6.7+ds1/src/examples/jack_streson.cpp Examining data/sndobj-2.6.7+ds1/src/examples/ladspa_example.cpp Examining data/sndobj-2.6.7+ds1/src/examples/Ladspaplug.cpp Examining data/sndobj-2.6.7+ds1/src/examples/Ladspaplug.h Examining data/sndobj-2.6.7+ds1/src/examples/midisynth.cpp Examining data/sndobj-2.6.7+ds1/src/examples/morph_tilde.cpp Examining data/sndobj-2.6.7+ds1/src/examples/pluck.cpp Examining data/sndobj-2.6.7+ds1/src/examples/rtschroeder.cpp Examining data/sndobj-2.6.7+ds1/src/examples/schroeder.cpp Examining data/sndobj-2.6.7+ds1/src/examples/sinus.cpp Examining data/sndobj-2.6.7+ds1/src/examples/streson.cpp Examining data/sndobj-2.6.7+ds1/src/examples/test.cpp Examining data/sndobj-2.6.7+ds1/src/examples/transpose.cpp Examining data/sndobj-2.6.7+ds1/src/FastOsc.cpp Examining data/sndobj-2.6.7+ds1/src/FastOsc.h Examining data/sndobj-2.6.7+ds1/src/FFT.h Examining data/sndobj-2.6.7+ds1/src/FFT_alt.cpp Examining data/sndobj-2.6.7+ds1/src/FFT_alt.h Examining data/sndobj-2.6.7+ds1/src/Filter.cpp Examining data/sndobj-2.6.7+ds1/src/Filter.h Examining data/sndobj-2.6.7+ds1/src/Fir.cpp Examining data/sndobj-2.6.7+ds1/src/Fir.h Examining data/sndobj-2.6.7+ds1/src/Gain.cpp Examining data/sndobj-2.6.7+ds1/src/Gain.h Examining data/sndobj-2.6.7+ds1/src/HammingTable.cpp Examining data/sndobj-2.6.7+ds1/src/HammingTable.h Examining data/sndobj-2.6.7+ds1/src/HarmTable.cpp Examining data/sndobj-2.6.7+ds1/src/HarmTable.h Examining data/sndobj-2.6.7+ds1/src/Hilb.cpp Examining data/sndobj-2.6.7+ds1/src/Hilb.h Examining data/sndobj-2.6.7+ds1/src/HiPass.cpp Examining data/sndobj-2.6.7+ds1/src/HiPass.h Examining data/sndobj-2.6.7+ds1/src/IADSR.cpp Examining data/sndobj-2.6.7+ds1/src/IADSR.h Examining data/sndobj-2.6.7+ds1/src/IFAdd.h Examining data/sndobj-2.6.7+ds1/src/IFFT.h Examining data/sndobj-2.6.7+ds1/src/IFFT_alt.cpp Examining data/sndobj-2.6.7+ds1/src/IFFT_alt.h Examining data/sndobj-2.6.7+ds1/src/IFGram.cpp Examining data/sndobj-2.6.7+ds1/src/IFGram.h Examining data/sndobj-2.6.7+ds1/src/ImpulseTable.cpp Examining data/sndobj-2.6.7+ds1/src/ImpulseTable.h Examining data/sndobj-2.6.7+ds1/src/Interp.cpp Examining data/sndobj-2.6.7+ds1/src/Interp.h Examining data/sndobj-2.6.7+ds1/src/Lookup.cpp Examining data/sndobj-2.6.7+ds1/src/Lookup.h Examining data/sndobj-2.6.7+ds1/src/Lookupi.cpp Examining data/sndobj-2.6.7+ds1/src/Lookupi.h Examining data/sndobj-2.6.7+ds1/src/Loop.cpp Examining data/sndobj-2.6.7+ds1/src/Loop.h Examining data/sndobj-2.6.7+ds1/src/LoPassTable.cpp Examining data/sndobj-2.6.7+ds1/src/LoPassTable.h Examining data/sndobj-2.6.7+ds1/src/LowPass.cpp Examining data/sndobj-2.6.7+ds1/src/LowPass.h Examining data/sndobj-2.6.7+ds1/src/Lp.cpp Examining data/sndobj-2.6.7+ds1/src/Lp.h Examining data/sndobj-2.6.7+ds1/src/MidiIn.cpp Examining data/sndobj-2.6.7+ds1/src/MidiIn.h Examining data/sndobj-2.6.7+ds1/src/MidiMap.cpp Examining data/sndobj-2.6.7+ds1/src/MidiMap.h Examining data/sndobj-2.6.7+ds1/src/Mix.cpp Examining data/sndobj-2.6.7+ds1/src/Mix.h Examining data/sndobj-2.6.7+ds1/src/NoteTable.cpp Examining data/sndobj-2.6.7+ds1/src/NoteTable.h Examining data/sndobj-2.6.7+ds1/src/Osc.cpp Examining data/sndobj-2.6.7+ds1/src/Osc.h Examining data/sndobj-2.6.7+ds1/src/Osci.cpp Examining data/sndobj-2.6.7+ds1/src/Osci.h Examining data/sndobj-2.6.7+ds1/src/Oscil.cpp Examining data/sndobj-2.6.7+ds1/src/Oscil.h Examining data/sndobj-2.6.7+ds1/src/Oscili.cpp Examining data/sndobj-2.6.7+ds1/src/Oscili.h Examining data/sndobj-2.6.7+ds1/src/Oscilt.cpp Examining data/sndobj-2.6.7+ds1/src/Oscilt.h Examining data/sndobj-2.6.7+ds1/src/Pan.cpp Examining data/sndobj-2.6.7+ds1/src/Pan.h Examining data/sndobj-2.6.7+ds1/src/Phase.cpp Examining data/sndobj-2.6.7+ds1/src/Phase.h Examining data/sndobj-2.6.7+ds1/src/PhOscili.cpp Examining data/sndobj-2.6.7+ds1/src/PhOscili.h Examining data/sndobj-2.6.7+ds1/src/Pitch.cpp Examining data/sndobj-2.6.7+ds1/src/Pitch.h Examining data/sndobj-2.6.7+ds1/src/PlnTable.cpp Examining data/sndobj-2.6.7+ds1/src/PlnTable.h Examining data/sndobj-2.6.7+ds1/src/Pluck.cpp Examining data/sndobj-2.6.7+ds1/src/Pluck.h Examining data/sndobj-2.6.7+ds1/src/Ptrack.cpp Examining data/sndobj-2.6.7+ds1/src/Ptrack.h Examining data/sndobj-2.6.7+ds1/src/PVA.h Examining data/sndobj-2.6.7+ds1/src/PVBlur.cpp Examining data/sndobj-2.6.7+ds1/src/PVBlur.h Examining data/sndobj-2.6.7+ds1/src/PVEnvTable.cpp Examining data/sndobj-2.6.7+ds1/src/PVEnvTable.h Examining data/sndobj-2.6.7+ds1/src/PVFilter.cpp Examining data/sndobj-2.6.7+ds1/src/PVFilter.h Examining data/sndobj-2.6.7+ds1/src/PVMask.cpp Examining data/sndobj-2.6.7+ds1/src/PVMask.h Examining data/sndobj-2.6.7+ds1/src/PVMix.cpp Examining data/sndobj-2.6.7+ds1/src/PVMix.h Examining data/sndobj-2.6.7+ds1/src/PVMorph.cpp Examining data/sndobj-2.6.7+ds1/src/PVMorph.h Examining data/sndobj-2.6.7+ds1/src/PVRead.h Examining data/sndobj-2.6.7+ds1/src/PVS.h Examining data/sndobj-2.6.7+ds1/src/PVTable.cpp Examining data/sndobj-2.6.7+ds1/src/PVTable.h Examining data/sndobj-2.6.7+ds1/src/PVTransp.cpp Examining data/sndobj-2.6.7+ds1/src/PVTransp.h Examining data/sndobj-2.6.7+ds1/src/Rand.cpp Examining data/sndobj-2.6.7+ds1/src/Rand.h Examining data/sndobj-2.6.7+ds1/src/Randh.cpp Examining data/sndobj-2.6.7+ds1/src/Randh.h Examining data/sndobj-2.6.7+ds1/src/Randi.cpp Examining data/sndobj-2.6.7+ds1/src/Randi.h Examining data/sndobj-2.6.7+ds1/src/Reson.cpp Examining data/sndobj-2.6.7+ds1/src/Reson.h Examining data/sndobj-2.6.7+ds1/src/ReSyn.h Examining data/sndobj-2.6.7+ds1/src/rfftw/cfft.c Examining data/sndobj-2.6.7+ds1/src/rfftw/config.c Examining data/sndobj-2.6.7+ds1/src/rfftw/executor.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_1.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_11.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_12.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_128.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_13.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_14.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_15.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fcr_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fftwnd.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhb_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fhf_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_1.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_11.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_12.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_13.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_14.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_15.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fn_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_1.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_11.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_12.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_13.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_14.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_15.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/fni_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_1.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_11.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_12.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_128.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_13.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_14.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_15.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/frc_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftw_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_10.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_16.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_3.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_32.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_4.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_5.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_6.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_64.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_7.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_8.c Examining data/sndobj-2.6.7+ds1/src/rfftw/ftwi_9.c Examining data/sndobj-2.6.7+ds1/src/rfftw/generic.c Examining data/sndobj-2.6.7+ds1/src/rfftw/malloc.c Examining data/sndobj-2.6.7+ds1/src/rfftw/planner.c Examining data/sndobj-2.6.7+ds1/src/rfftw/putils.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rader.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rconfig.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rexec.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rexec2.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rfftwf77.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rfftwnd.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rgeneric.c Examining data/sndobj-2.6.7+ds1/src/rfftw/rplanner.c Examining data/sndobj-2.6.7+ds1/src/rfftw/timer.c Examining data/sndobj-2.6.7+ds1/src/rfftw/twiddle.c Examining data/sndobj-2.6.7+ds1/src/rfftw/wisdom.c Examining data/sndobj-2.6.7+ds1/src/rfftw/wisdomio.c Examining data/sndobj-2.6.7+ds1/src/Ring.cpp Examining data/sndobj-2.6.7+ds1/src/Ring.h Examining data/sndobj-2.6.7+ds1/src/SinAnal.h Examining data/sndobj-2.6.7+ds1/src/SinSyn.h Examining data/sndobj-2.6.7+ds1/src/SndAiff.cpp Examining data/sndobj-2.6.7+ds1/src/SndAiff.h Examining data/sndobj-2.6.7+ds1/src/SndASIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndASIO.h Examining data/sndobj-2.6.7+ds1/src/SndBuffer.cpp Examining data/sndobj-2.6.7+ds1/src/SndBuffer.h Examining data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp Examining data/sndobj-2.6.7+ds1/src/SndCoreAudio.h Examining data/sndobj-2.6.7+ds1/src/SndFIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndFIO.h Examining data/sndobj-2.6.7+ds1/src/SndIn.cpp Examining data/sndobj-2.6.7+ds1/src/SndIn.h Examining data/sndobj-2.6.7+ds1/src/SndIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndIO.h Examining data/sndobj-2.6.7+ds1/src/SndJackIO.h Examining data/sndobj-2.6.7+ds1/src/SndMidi.cpp Examining data/sndobj-2.6.7+ds1/src/SndMidi.h Examining data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp Examining data/sndobj-2.6.7+ds1/src/SndMidiIn.h Examining data/sndobj-2.6.7+ds1/src/SndObj.cpp Examining data/sndobj-2.6.7+ds1/src/SndObj.h Examining data/sndobj-2.6.7+ds1/src/SndPVOCEX.cpp Examining data/sndobj-2.6.7+ds1/src/SndPVOCEX.h Examining data/sndobj-2.6.7+ds1/src/SndRead.h Examining data/sndobj-2.6.7+ds1/src/SndRTIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndRTIO.h Examining data/sndobj-2.6.7+ds1/src/SndRTThread.cpp Examining data/sndobj-2.6.7+ds1/src/SndRTThread.h Examining data/sndobj-2.6.7+ds1/src/SndSinIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndSinIO.h Examining data/sndobj-2.6.7+ds1/src/SndTable.cpp Examining data/sndobj-2.6.7+ds1/src/SndTable.h Examining data/sndobj-2.6.7+ds1/src/SndThread.cpp Examining data/sndobj-2.6.7+ds1/src/SndThread.h Examining data/sndobj-2.6.7+ds1/src/SndWave.cpp Examining data/sndobj-2.6.7+ds1/src/SndWave.h Examining data/sndobj-2.6.7+ds1/src/SndWaveX.cpp Examining data/sndobj-2.6.7+ds1/src/SpecCart.cpp Examining data/sndobj-2.6.7+ds1/src/SpecCart.h Examining data/sndobj-2.6.7+ds1/src/SpecCombine.cpp Examining data/sndobj-2.6.7+ds1/src/SpecCombine.h Examining data/sndobj-2.6.7+ds1/src/SpecEnvTable.cpp Examining data/sndobj-2.6.7+ds1/src/SpecEnvTable.h Examining data/sndobj-2.6.7+ds1/src/SpecIn.cpp Examining data/sndobj-2.6.7+ds1/src/SpecIn.h Examining data/sndobj-2.6.7+ds1/src/SpecInterp.cpp Examining data/sndobj-2.6.7+ds1/src/SpecInterp.h Examining data/sndobj-2.6.7+ds1/src/SpecMult.cpp Examining data/sndobj-2.6.7+ds1/src/SpecMult.h Examining data/sndobj-2.6.7+ds1/src/SpecPolar.cpp Examining data/sndobj-2.6.7+ds1/src/SpecPolar.h Examining data/sndobj-2.6.7+ds1/src/SpecSplit.cpp Examining data/sndobj-2.6.7+ds1/src/SpecSplit.h Examining data/sndobj-2.6.7+ds1/src/SpecThresh.cpp Examining data/sndobj-2.6.7+ds1/src/SpecThresh.h Examining data/sndobj-2.6.7+ds1/src/SpecVoc.cpp Examining data/sndobj-2.6.7+ds1/src/SpecVoc.h Examining data/sndobj-2.6.7+ds1/src/StringFlt.cpp Examining data/sndobj-2.6.7+ds1/src/StringFlt.h Examining data/sndobj-2.6.7+ds1/src/SyncGrain.cpp Examining data/sndobj-2.6.7+ds1/src/SyncGrain.h Examining data/sndobj-2.6.7+ds1/src/Table.h Examining data/sndobj-2.6.7+ds1/src/Tap.cpp Examining data/sndobj-2.6.7+ds1/src/Tap.h Examining data/sndobj-2.6.7+ds1/src/Tapi.cpp Examining data/sndobj-2.6.7+ds1/src/Tapi.h Examining data/sndobj-2.6.7+ds1/src/templates/application_template.cpp Examining data/sndobj-2.6.7+ds1/src/templates/class_template.cpp Examining data/sndobj-2.6.7+ds1/src/templates/class_template.h Examining data/sndobj-2.6.7+ds1/src/TpTz.cpp Examining data/sndobj-2.6.7+ds1/src/TpTz.h Examining data/sndobj-2.6.7+ds1/src/TrisegTable.cpp Examining data/sndobj-2.6.7+ds1/src/TrisegTable.h Examining data/sndobj-2.6.7+ds1/src/Unit.cpp Examining data/sndobj-2.6.7+ds1/src/Unit.h Examining data/sndobj-2.6.7+ds1/src/UsrDefTable.cpp Examining data/sndobj-2.6.7+ds1/src/UsrDefTable.h Examining data/sndobj-2.6.7+ds1/src/UsrHarmTable.cpp Examining data/sndobj-2.6.7+ds1/src/UsrHarmTable.h Examining data/sndobj-2.6.7+ds1/src/VDelay.cpp Examining data/sndobj-2.6.7+ds1/src/VDelay.h Examining data/sndobj-2.6.7+ds1/src/AdSyn.cpp Examining data/sndobj-2.6.7+ds1/src/FFT.cpp Examining data/sndobj-2.6.7+ds1/src/IFAdd.cpp Examining data/sndobj-2.6.7+ds1/src/IFFT.cpp Examining data/sndobj-2.6.7+ds1/src/PVA.cpp Examining data/sndobj-2.6.7+ds1/src/PVRead.cpp Examining data/sndobj-2.6.7+ds1/src/PVS.cpp Examining data/sndobj-2.6.7+ds1/src/ReSyn.cpp Examining data/sndobj-2.6.7+ds1/src/SinSyn.cpp Examining data/sndobj-2.6.7+ds1/src/SndRead.cpp Examining data/sndobj-2.6.7+ds1/src/SinAnal.cpp Examining data/sndobj-2.6.7+ds1/src/SndJackIO.cpp Examining data/sndobj-2.6.7+ds1/src/SndWaveX.h Examining data/sndobj-2.6.7+ds1/trane/Instrument.cpp Examining data/sndobj-2.6.7+ds1/trane/Instrument.h Examining data/sndobj-2.6.7+ds1/trane/main.cpp FINAL RESULTS: data/sndobj-2.6.7+ds1/src/SndASIO.cpp:535:5: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(name, drivernames[num]); data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp:338:5: [4] (buffer) strcat: Does not check for buffer overflows when concatenating to destination [MS-banned] (CWE-120). Consider using strcat_s, strncat, strlcat, or snprintf (warning: strncat is easily misused). strcat(name2, name); data/sndobj-2.6.7+ds1/src/SndMidi.cpp:163:12: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). return strcpy(name, incaps.szPname); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1642:12: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). return strcpy(name, incaps.szPname); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1650:12: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). return strcpy(name, outcaps.szPname); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:87:8: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(lpdrv->drvname,databuf); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:89:12: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). else strcpy(lpdrv->drvname,keyname); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:224:4: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(drvname,lpdrv->drvname); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:246:4: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(dllpath,lpdrv->dllpath); data/sndobj-2.6.7+ds1/src/examples/schroeder.cpp:49:2: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(infile, argv[1]); data/sndobj-2.6.7+ds1/src/examples/schroeder.cpp:50:2: [4] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). strcpy(outfile, argv[2]); data/sndobj-2.6.7+ds1/src/Rand.cpp:36:3: [3] (random) srand: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. srand((unsigned)time(0)); data/sndobj-2.6.7+ds1/src/Rand.cpp:44:3: [3] (random) srand: This function is not sufficiently random for security-related functions such as key and nonce creation (CWE-327). Use a more secure technique for acquiring random values. srand((unsigned)time(0)); data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:35:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FORM_ID[4] = {'F','O','R','M'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:36:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char COMM_ID[4] = {'C','O','M','M'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:37:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char MARK_ID[4] = {'M','A','R','K'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:38:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char INST_ID[4] = {'I','N','S','T'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:39:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char SSND_ID[4] = {'S','S','N','D'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:40:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FORM_TYPE[4] = {'A','I','F','F'}; data/sndobj-2.6.7+ds1/include/SndObj/SndAiff.h:64:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sampleRate[10]; // 80-bit extended value data/sndobj-2.6.7+ds1/include/SndObj/SndFIO.h:111:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[2]; data/sndobj-2.6.7+ds1/include/SndObj/SndFIO.h:126:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[4]; data/sndobj-2.6.7+ds1/include/SndObj/SndFIO.h:144:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[4]; data/sndobj-2.6.7+ds1/include/SndObj/SndFIO.h:161:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[8]; data/sndobj-2.6.7+ds1/include/SndObj/SndIO.h:76:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char s[3]; data/sndobj-2.6.7+ds1/include/SndObj/SndMidi.h:73:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char msg[4]; // message bytes data/sndobj-2.6.7+ds1/include/SndObj/SndMidi.h:85:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char msg[4]; data/sndobj-2.6.7+ds1/include/SndObj/SndWave.h:35:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char RIFF_ID[4] = {'R','I','F','F'}; data/sndobj-2.6.7+ds1/include/SndObj/SndWave.h:36:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char WAVE_ID[4] = {'W','A','V','E'}; data/sndobj-2.6.7+ds1/include/SndObj/SndWave.h:37:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FMT_ID[4] = {'f','m','t',' '}; data/sndobj-2.6.7+ds1/include/SndObj/SndWave.h:38:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char DATA_ID[4] = {'d','a','t','a'}; data/sndobj-2.6.7+ds1/include/SndObj/SndWaveX.h:72:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char Data4[8]; data/sndobj-2.6.7+ds1/include/asio.h:229:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ieee[8]; data/sndobj-2.6.7+ds1/include/asio.h:465:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[64]; data/sndobj-2.6.7+ds1/include/asio.h:511:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char reserved[12]; data/sndobj-2.6.7+ds1/include/asio.h:957:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; data/sndobj-2.6.7+ds1/include/asio.h:959:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errorMessage[124]; data/sndobj-2.6.7+ds1/include/asio.h:1365:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; // for user selection data/sndobj-2.6.7+ds1/include/asio.h:1543:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; // dto data/sndobj-2.6.7+ds1/include/asio.h:1885:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[32]; data/sndobj-2.6.7+ds1/include/asio.h:1903:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[64]; data/sndobj-2.6.7+ds1/include/asio.h:2005:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[512-sizeof(ASIOIoFormatType)]; data/sndobj-2.6.7+ds1/include/asiolist.h:16:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dllpath[MAXPATHLEN]; data/sndobj-2.6.7+ds1/include/asiolist.h:17:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char drvname[MAXDRVNAMELEN]; data/sndobj-2.6.7+ds1/src/SndASIO.cpp:394:10: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. union { char c[4]; long l;} tmp; data/sndobj-2.6.7+ds1/src/SndASIO.cpp:429:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tmp[4]; data/sndobj-2.6.7+ds1/src/SndAiff.cpp:172:16: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if(!(m_file = fopen(m_name, "r+b"))) data/sndobj-2.6.7+ds1/src/SndAiff.cpp:225:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char temp[4]; data/sndobj-2.6.7+ds1/src/SndAiff.cpp:312:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tmp[4]; data/sndobj-2.6.7+ds1/src/SndAiff.h:35:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FORM_ID[4] = {'F','O','R','M'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:36:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char COMM_ID[4] = {'C','O','M','M'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:37:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char MARK_ID[4] = {'M','A','R','K'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:38:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char INST_ID[4] = {'I','N','S','T'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:39:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char SSND_ID[4] = {'S','S','N','D'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:40:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FORM_TYPE[4] = {'A','I','F','F'}; data/sndobj-2.6.7+ds1/src/SndAiff.h:64:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char sampleRate[10]; // 80-bit extended value data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp:336:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(name2, "%u: ", list[i]); data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp:346:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char *devs[50]; data/sndobj-2.6.7+ds1/src/SndFIO.cpp:78:17: [2] (misc) fopen: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if ((m_file = fopen(name,s_temp)) != NULL) m_filestat=SFOPEN; data/sndobj-2.6.7+ds1/src/SndFIO.h:111:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[2]; data/sndobj-2.6.7+ds1/src/SndFIO.h:126:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[4]; data/sndobj-2.6.7+ds1/src/SndFIO.h:144:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[4]; data/sndobj-2.6.7+ds1/src/SndFIO.h:161:14: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char uc[8]; data/sndobj-2.6.7+ds1/src/SndIO.h:76:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char s[3]; data/sndobj-2.6.7+ds1/src/SndJackIO.cpp:55:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char port_name[10]; data/sndobj-2.6.7+ds1/src/SndJackIO.cpp:100:7: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(port_name, "in%d", i+1); data/sndobj-2.6.7+ds1/src/SndJackIO.cpp:135:7: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(port_name, "out%d", i+1); data/sndobj-2.6.7+ds1/src/SndMidi.h:73:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char msg[4]; // message bytes data/sndobj-2.6.7+ds1/src/SndMidi.h:85:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char msg[4]; data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:35:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if(!(m_fd = open(m_port, O_RDONLY))) data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:82:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if(!(m_fd = open(m_port, O_RDONLY))) data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:247:10: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char temp[2]; data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:90:25: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. m_pwhdr[n]->lpData = (char *) m_buffer[n]; data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:99:11: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. m_cp = (char *) m_buffer[m_ndx]; data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:494:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if((m_dev = open(device, O_RDONLY)) == -1){ data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:502:13: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). if((m_dev = open(device, O_WRONLY)) == -1){ data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:844:13: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. m_cp = (char *) m_buffer[m_ndx]; data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:920:13: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. m_cp = (char *) m_buffer[m_ndx]; data/sndobj-2.6.7+ds1/src/SndWave.cpp:248:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char chunk_id[4]; data/sndobj-2.6.7+ds1/src/SndWave.cpp:304:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char tmp[4]; data/sndobj-2.6.7+ds1/src/SndWave.cpp:352:15: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. union { char c[4]; int l;} tmp; data/sndobj-2.6.7+ds1/src/SndWave.h:35:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char RIFF_ID[4] = {'R','I','F','F'}; data/sndobj-2.6.7+ds1/src/SndWave.h:36:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char WAVE_ID[4] = {'W','A','V','E'}; data/sndobj-2.6.7+ds1/src/SndWave.h:37:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char FMT_ID[4] = {'f','m','t',' '}; data/sndobj-2.6.7+ds1/src/SndWave.h:38:7: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. const char DATA_ID[4] = {'d','a','t','a'}; data/sndobj-2.6.7+ds1/src/SndWaveX.h:72:12: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. unsigned char Data4[8]; data/sndobj-2.6.7+ds1/src/asio/asio.cpp:54:2: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->name, "No ASIO Driver"); data/sndobj-2.6.7+ds1/src/asio/asio.cpp:58:3: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->errorMessage, "Not enough memory for the ASIO driver!"); data/sndobj-2.6.7+ds1/src/asio/asio.cpp:68:2: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->errorMessage, "No ASIO Driver Error"); data/sndobj-2.6.7+ds1/src/asio/asio.cpp:76:2: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->name, "No ASIO Driver"); data/sndobj-2.6.7+ds1/src/asio/asio.cpp:86:3: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->errorMessage, "No ASIO Driver Error"); data/sndobj-2.6.7+ds1/src/asio/asio.cpp:205:3: [2] (buffer) strcpy: Does not check for buffer overflows when copying to destination [MS-banned] (CWE-120). Consider using snprintf, strcpy_s, or strlcpy (warning: strncpy easily misused). Risk is low because the source is a constant string. strcpy(info->name, "None"); data/sndobj-2.6.7+ds1/src/asio/asio.h:229:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char ieee[8]; data/sndobj-2.6.7+ds1/src/asio/asio.h:465:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[64]; data/sndobj-2.6.7+ds1/src/asio/asio.h:511:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char reserved[12]; data/sndobj-2.6.7+ds1/src/asio/asio.h:957:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; data/sndobj-2.6.7+ds1/src/asio/asio.h:959:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char errorMessage[124]; data/sndobj-2.6.7+ds1/src/asio/asio.h:1365:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; // for user selection data/sndobj-2.6.7+ds1/src/asio/asio.h:1543:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char name[32]; // dto data/sndobj-2.6.7+ds1/src/asio/asio.h:1885:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[32]; data/sndobj-2.6.7+ds1/src/asio/asio.h:1903:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[64]; data/sndobj-2.6.7+ds1/src/asio/asio.h:2005:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char future[512-sizeof(ASIOIoFormatType)]; data/sndobj-2.6.7+ds1/src/asio/asiodrivers.cpp:50:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dname[64]; data/sndobj-2.6.7+ds1/src/asio/asiodrivers.cpp:116:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dname[64]; data/sndobj-2.6.7+ds1/src/asio/asiodrivers.cpp:117:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char curName[64]; data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:16:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char databuf[512]; data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:60:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char databuf[256]; data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:61:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dllpath[MAXPATHLEN]; data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:79:7: [2] (buffer) MultiByteToWideChar: Requires maximum length in CHARACTERS, not bytes (CWE-120). MultiByteToWideChar(CP_ACP,0,(LPCSTR)databuf,-1,(LPWSTR)wData,100); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:81:8: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(&lpdrv->clsid,&clsid,sizeof(CLSID)); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:133:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char keyname[MAXDRVNAMELEN]; data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:227:4: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(drvname,lpdrv->drvname,drvnamesize-4); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:262:3: [2] (buffer) memcpy: Does not check for buffer overflows when copying to destination (CWE-120). Make sure destination can always hold the source data. memcpy(clsid,&lpdrv->clsid,sizeof(CLSID)); data/sndobj-2.6.7+ds1/src/asio/asiolist.h:16:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char dllpath[MAXPATHLEN]; data/sndobj-2.6.7+ds1/src/asio/asiolist.h:17:2: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char drvname[MAXDRVNAMELEN]; data/sndobj-2.6.7+ds1/src/examples/harmonise.cpp:15:13: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). formants = atoi(argv[3]); data/sndobj-2.6.7+ds1/src/examples/jack_streson.cpp:53:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). datafile.open(argv[3]); data/sndobj-2.6.7+ds1/src/examples/midisynth.cpp:54:13: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). harmonics = atoi(argv[2]); // no of harmonics data/sndobj-2.6.7+ds1/src/examples/midisynth.cpp:57:8: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). atoi data/sndobj-2.6.7+ds1/src/examples/pluck.cpp:29:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char port[50]; // port is char on OSS/Irix data/sndobj-2.6.7+ds1/src/examples/schroeder.cpp:25:1: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char infile[128], outfile[128]; data/sndobj-2.6.7+ds1/src/examples/sinus.cpp:26:17: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). int intracks = atoi(argv[6]); // analysis max number of tracks data/sndobj-2.6.7+ds1/src/examples/sinus.cpp:27:17: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). int outracks = atoi(argv[7]); // synthesis */ data/sndobj-2.6.7+ds1/src/examples/streson.cpp:60:14: [2] (misc) open: Check when opening files - can an attacker redirect it (via symlinks), force the opening of special file type (e.g., device files), move things around to create a race condition, control its ancestors, or change its contents? (CWE-362). datafile.open(argv[3]); data/sndobj-2.6.7+ds1/src/examples/transpose.cpp:15:13: [2] (integer) atoi: Unless checked, the resulting number can exceed the expected range (CWE-190). If source untrusted, check both minimum and maximum, even if the input had no minus sign (large numbers can roll over into negative number; consider saving to an unsigned value if that is intended). formants = atoi(argv[3]); data/sndobj-2.6.7+ds1/src/rfftw/cfft.c:392:34: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. free((char *)p[s]);free((char *)q[s]); data/sndobj-2.6.7+ds1/src/rfftw/cfft.c:392:53: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. free((char *)p[s]);free((char *)q[s]); data/sndobj-2.6.7+ds1/src/rfftw/wisdom.c:151:6: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char buf[128]; data/sndobj-2.6.7+ds1/src/rfftw/wisdom.c:153:6: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(buf, "%d", n); data/sndobj-2.6.7+ds1/src/templates/application_template.cpp:14:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char command[10]; data/sndobj-2.6.7+ds1/trane/main.cpp:84:3: [2] (buffer) char: Statically-sized arrays can be improperly restricted, leading to potential overflows or other issues (CWE-119!/CWE-120). Perform bounds checking, use functions that limit length, or ensure that the size is larger than the maximum possible length. char mess1[4][10], mess2[4][10]; data/sndobj-2.6.7+ds1/trane/main.cpp:100:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(mess1[i], "string %d", i+1); data/sndobj-2.6.7+ds1/trane/main.cpp:137:5: [2] (buffer) sprintf: Does not check for buffer overflows (CWE-120). Use sprintf_s, snprintf, or vsnprintf. Risk is low because the source has a constant maximum length. sprintf(mess2[i], "sample %d", i+1); data/sndobj-2.6.7+ds1/include/SndObj/SndBuffer.h:60:5: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. usleep(1); data/sndobj-2.6.7+ds1/src/SndBuffer.h:60:5: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. usleep(1); data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp:247:34: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while(!m_outused[m_outcurbuff]) usleep(m_sleept); data/sndobj-2.6.7+ds1/src/SndCoreAudio.cpp:282:32: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while(!m_inused[m_incurbuff]) usleep(m_sleept); data/sndobj-2.6.7+ds1/src/SndJackIO.cpp:299:34: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while(!m_outused[m_outcurbuff]) usleep(100); data/sndobj-2.6.7+ds1/src/SndJackIO.cpp:320:32: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while(!m_inused[m_incurbuff]) usleep(100); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:250:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:260:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:262:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:271:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:273:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:288:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:290:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:299:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:301:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:309:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:316:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:323:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndMidiIn.cpp:325:1: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). read(m_fd, temp, 1); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1136:16: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). m_items = read(m_dev, m_cp, m_buffsize); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1154:15: [1] (buffer) read: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). m_items = read(m_dev, m_sp, m_buffsize); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1355:43: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while (snd_pcm_resume(m_dev) == -EAGAIN) usleep(1); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1387:43: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while (snd_pcm_resume(m_dev) == -EAGAIN) usleep(1); data/sndobj-2.6.7+ds1/src/SndRTIO.cpp:1419:43: [1] (obsolete) usleep: This C routine is considered obsolete (as opposed to the shell command by the same name). The interaction of this function with SIGALRM and other timer functions such as sleep(), alarm(), setitimer(), and nanosleep() is unspecified (CWE-676). Use nanosleep(2) or setitimer(2) instead. while (snd_pcm_resume(m_dev) == -EAGAIN) usleep(1); data/sndobj-2.6.7+ds1/src/SndRead.cpp:56:14: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). int size = strlen(name); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:24:25: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). CharLowerBuff(clsidstr,strlen(clsidstr)); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:31:27: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). CharLowerBuff(databuf,strlen(databuf)); data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:223:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(lpdrv->drvname) < (unsigned int)drvnamesize) { data/sndobj-2.6.7+ds1/src/asio/asiolist.cpp:245:7: [1] (buffer) strlen: Does not handle strings that are not \0-terminated; if given one it may perform an over-read (it could cause a crash if unprotected) (CWE-126). if (strlen(lpdrv->dllpath) < (unsigned int)dllpathsize) { data/sndobj-2.6.7+ds1/src/rfftw/wisdomio.c:40:13: [1] (buffer) getc: Check buffer boundaries if used in a loop including recursive loops (CWE-120, CWE-20). return getc((FILE *) data); ANALYSIS SUMMARY: Hits = 163 Lines analyzed = 113001 in approximately 2.17 seconds (52144 lines/second) Physical Source Lines of Code (SLOC) = 81763 Hits@level = [0] 70 [1] 30 [2] 120 [3] 2 [4] 11 [5] 0 Hits@level+ = [0+] 233 [1+] 163 [2+] 133 [3+] 13 [4+] 11 [5+] 0 Hits/KSLOC@level+ = [0+] 2.8497 [1+] 1.99357 [2+] 1.62665 [3+] 0.158996 [4+] 0.134535 [5+] 0 Dot directories skipped = 1 (--followdotdir overrides) Minimum risk level = 1 Not every hit is necessarily a security vulnerability. There may be other security vulnerabilities; review your code! See 'Secure Programming HOWTO' (https://dwheeler.com/secure-programs) for more information.