Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Audiofile

First CVE: Mar 15, 2017Active for: 9 yearsTotal CVEs: 20
28.7
VTI Score
Low

Audiofile is a focused audio-processing library that, despite a modest product portfolio, occupies a prominent position in the multimedia software supply chain where it is embedded across a broad range of audio applications and media players. The vendor's vulnerability surface concentrates in its core audiofile library and is characterized by a recurring set of memory-safety weaknesses—including improper buffer restrictions, NULL-pointer dereferences, divide-by-zero conditions, integer overflows, and out-of-bounds writes—typical of C/C++ parsers handling untrusted audio formats. These weakness classes reflect the low-level data-handling demands of audio decoding and can propagate to any downstream application that links the library, making remediation dependent on the speed of dependent vendors in rebuilding and distributing patched versions. Defenders should track this library's releases independently of individual downstream products and consider it a supply-chain dependency requiring proactive monitoring; current severity, exploitation status, and exposure counts are shown alongside this summary.

FAUCET AI Generated
20
Total CVEs
More Total CVEs than 96% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Audiofile over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2017
9 years ago
Most Recent CVE
Oct 23, 2025
274 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-17095HIGH
An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run ha
Sep 16, 20188.829NONO
CVE-2015-7747HIGH
Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program cras
Feb 19, 20208.828NONO
CVE-2025-50950HIGH
Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function.
Oct 23, 20257.526NONO
CVE-2017-6828HIGH
Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impa
Mar 15, 20177.825NONO
CVE-2017-6827HIGH
Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to ha
Mar 15, 20177.825NONO
CVE-2022-24599MEDIUM
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a craf
Feb 24, 20226.522NONO
CVE-2019-13147MEDIUM
In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial
Jul 2, 20196.522NONO
CVE-2018-13440MEDIUM
The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service vi
Jul 8, 20186.522NONO
CVE-2017-6839MEDIUM
Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
Mar 20, 20175.521NONO
CVE-2017-6838MEDIUM
Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file.
Mar 20, 20175.521NONO
View all 20 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products20 CVEs
75%
25%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local14 (70.0%)
Network6 (30.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (5.0%)
Unknown0 (0.0%)
Required19 (95.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None20 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Audiofile.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Audiofile — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Audiofile's Products

View all 1 CNAs →

Top CWEs