VYPR

Vendor CVEs

Audiofile

All CVEs

21 total · sorted by risk
  • CVE-2018-17095HigSep 16, 2018
    risk 0.58cvss 8.8epss 0.05

    An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

  • CVE-2015-7747HigFeb 19, 2020
    risk 0.51cvss 8.8epss 0.09

    Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by…

  • CVE-2017-6828HigMar 15, 2017
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted WAV file.

  • CVE-2017-6827HigMar 15, 2017
    risk 0.51cvss 7.8epss 0.03

    Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impact via a crafted audio file.

  • CVE-2025-50950HigOct 23, 2025
    risk 0.49cvss 7.5epss 0.00

    Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.

  • CVE-2022-24599MedFeb 24, 2022
    risk 0.42cvss 6.5epss 0.02

    In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it…

  • CVE-2019-13147MedJul 2, 2019
    risk 0.42cvss 6.5epss 0.02

    In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial of service via a crafted file.

  • CVE-2018-13440MedJul 8, 2018
    risk 0.42cvss 6.5epss 0.03

    The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service via a crafted caf file, as demonstrated by sfconvert.

  • CVE-2020-18781MedAug 22, 2023
    risk 0.36cvss 5.5epss 0.00

    Heap buffer overflow vulnerability in FilePOSIX::read in File.cpp in audiofile 0.3.6 may cause denial-of-service via a crafted wav file, this bug can be triggered by the executable sfconvert.

  • CVE-2017-6839MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6838MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6837MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    WAVE.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via vectors related to a large number of coefficients.

  • CVE-2017-6836MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap-based buffer overflow in the Expand3To4Module::run function in libaudiofile/modules/SimpleModule.h in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6835MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    The reset1 function in libaudiofile/modules/BlockCodec.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted file.

  • CVE-2017-6834MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap-based buffer overflow in the ulaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6833MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    The runPull function in libaudiofile/modules/BlockCodec.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a crafted file.

  • CVE-2017-6832MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap-based buffer overflow in the decodeBlock in MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0, 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6831MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap-based buffer overflow in the decodeBlockWAVE function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0 and 0.2.7 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6830MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    Heap-based buffer overflow in the alaw2linear_buf function in G711.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2017-6829MedMar 20, 2017
    risk 0.36cvss 5.5epss 0.03

    The decodeSample function in IMA.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.

  • CVE-2008-5824Jan 2, 2009
    risk 0.03cvss epss 0.06

    Heap-based buffer overflow in msadpcm.c in libaudiofile in audiofile 0.2.6 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted WAV file.