In 'EXTRACTORwavextractmethod' function of wavextractor.c, the program does not check the value of samplerate, with a crafted file, the samplerate can be set to zero, resulting in a divide by zero and a crash (CVE-2017-15266).
NULL Pointer Dereference vulneribility in libextract when getting flac meta from libFlac (CVE-2017-15267).
NULL Pointer Dereference vulneribility in libextractor EXTRACTORnsfextract_method() (rhbz#1501695).