| CVE-2017-12562 | Cri | 0.64 | 9.8 | 0.02 | | Aug 5, 2017 | Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. |
| CVE-2017-6892 | Hig | 0.57 | 8.8 | 0.01 | | Jun 12, 2017 | In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file. |
| CVE-2017-8361 | Hig | 0.57 | 8.8 | 0.02 | | Apr 30, 2017 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file. |
| CVE-2026-37555 | Hig | 0.42 | 7.5 | 0.00 | | Apr 29, 2026 | An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication overflows before being assigned to sf.frames (sf_count_t/int64). With samplesperblock=50000 and blocks=50000, the product 2500000000 overflows to -1794967296. This causes incorrect frame count leading to heap buffer overflow or denial of service. Both values come from the WAV file header and are attacker-controlled. This issue was discovered after an incomplete fix for CVE-2022-33065. |
| CVE-2017-16942 | Med | 0.42 | 6.5 | 0.00 | | Nov 25, 2017 | In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file. |
| CVE-2017-14634 | Med | 0.42 | 6.5 | 0.01 | | Sep 21, 2017 | In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file. |
| CVE-2017-8365 | Med | 0.42 | 6.5 | 0.01 | | Apr 30, 2017 | The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file. |
| CVE-2017-8363 | Med | 0.42 | 6.5 | 0.01 | | Apr 30, 2017 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file. |
| CVE-2017-8362 | Med | 0.42 | 6.5 | 0.01 | | Apr 30, 2017 | The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file. |
| CVE-2017-7742 | Med | 0.36 | 5.5 | 0.00 | | Apr 12, 2017 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. |
| CVE-2017-7741 | Med | 0.36 | 5.5 | 0.00 | | Apr 12, 2017 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585. |
| CVE-2017-7586 | Med | 0.36 | 5.5 | 0.00 | | Apr 7, 2017 | In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. |
| CVE-2017-7585 | Med | 0.36 | 5.5 | 0.00 | | Apr 7, 2017 | In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file. |
| CVE-2014-9756 | | 0.00 | — | 0.01 | | Nov 19, 2015 | The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable. |
| CVE-2014-9496 | | 0.00 | — | 0.00 | | Jan 16, 2015 | The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read. |