VYPR
Vendor

Libsndfile Project

Products
2
CVEs
40
Across products
40
Status
Private

Products

2

Recent CVEs

40
View all 40 CVEs →
  • CVE-2017-12562CriAug 5, 2017
    risk 0.64cvss 9.8epss 0.04

    Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

  • CVE-2017-8361HigApr 30, 2017
    risk 0.58cvss 8.8epss 0.04

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

  • CVE-2018-13139HigJul 4, 2018
    risk 0.57cvss 8.8epss 0.04

    A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable…

  • CVE-2017-6892HigJun 12, 2017
    risk 0.57cvss 8.8epss 0.02

    In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.

  • CVE-2017-14246HigSep 21, 2017
    risk 0.53cvss 8.1epss 0.02

    An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

  • CVE-2017-14245HigSep 21, 2017
    risk 0.53cvss 8.1epss 0.02

    An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

  • CVE-2017-8365MedApr 30, 2017
    risk 0.43cvss 6.5epss 0.03

    The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.

  • CVE-2017-8363MedApr 30, 2017
    risk 0.43cvss 6.5epss 0.03

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

  • CVE-2017-8362MedApr 30, 2017
    risk 0.43cvss 6.5epss 0.03

    The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.

  • CVE-2026-37555HigApr 29, 2026
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 167) were not. When samplesperblock (int) * blocks (int) exceeds INT_MAX, the 32-bit multiplication…

  • CVE-2018-13419MedJul 7, 2018
    risk 0.42cvss 6.5epss 0.01

    An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

  • CVE-2017-16942MedNov 25, 2017
    risk 0.42cvss 6.5epss 0.01

    In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file.

  • CVE-2017-14634MedSep 21, 2017
    risk 0.42cvss 6.5epss 0.02

    In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.

  • CVE-2017-7742MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.01

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

  • CVE-2017-7741MedApr 12, 2017
    risk 0.36cvss 5.5epss 0.01

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

  • CVE-2017-7586MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

  • CVE-2017-7585MedApr 7, 2017
    risk 0.36cvss 5.5epss 0.01

    In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

  • CVE-2015-7805Nov 17, 2015
    risk 0.04cvss epss 0.13

    Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

  • CVE-2009-1791May 26, 2009
    risk 0.01cvss epss 0.07

    Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an…

  • CVE-2009-1788May 26, 2009
    risk 0.01cvss epss 0.08

    Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an…