Audiofile is a focused audio-processing library that, despite a modest product portfolio, occupies a prominent position in the multimedia software supply chain where it is embedded across a broad range of audio applications and media players. The vendor's vulnerability surface concentrates in its core audiofile library and is characterized by a recurring set of memory-safety weaknesses—including improper buffer restrictions, NULL-pointer dereferences, divide-by-zero conditions, integer overflows, and out-of-bounds writes—typical of C/C++ parsers handling untrusted audio formats. These weakness classes reflect the low-level data-handling demands of audio decoding and can propagate to any downstream application that links the library, making remediation dependent on the speed of dependent vendors in rebuilding and distributing patched versions. Defenders should track this library's releases independently of individual downstream products and consider it a supply-chain dependency requiring proactive monitoring; current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Audiofile over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-17095HIGH An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run ha | Sep 16, 2018 | 8.8 | 29 | NO | NO |
CVE-2015-7747HIGH Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program cras | Feb 19, 2020 | 8.8 | 28 | NO | NO |
CVE-2025-50950HIGH Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function. | Oct 23, 2025 | 7.5 | 26 | NO | NO |
CVE-2017-6828HIGH Heap-based buffer overflow in the readValue function in FileHandle.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to have unspecified impa | Mar 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-6827HIGH Heap-based buffer overflow in the MSADPCM::initializeCoefficients function in MSADPCM.cpp in audiofile (aka libaudiofile and Audio File Library) 0.3.6 allows remote attackers to ha | Mar 15, 2017 | 7.8 | 25 | NO | NO |
CVE-2022-24599MEDIUM In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a craf | Feb 24, 2022 | 6.5 | 22 | NO | NO |
CVE-2019-13147MEDIUM In Audio File Library (aka audiofile) 0.3.6, there exists one NULL pointer dereference bug in ulaw2linear_buf in G711.cpp in libmodules.a that allows an attacker to cause a denial | Jul 2, 2019 | 6.5 | 22 | NO | NO |
CVE-2018-13440MEDIUM The audiofile Audio File Library 0.3.6 has a NULL pointer dereference bug in ModuleState::setup in modules/ModuleState.cpp, which allows an attacker to cause a denial of service vi | Jul 8, 2018 | 6.5 | 22 | NO | NO |
CVE-2017-6839MEDIUM Integer overflow in modules/MSADPCM.cpp in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file. | Mar 20, 2017 | 5.5 | 21 | NO | NO |
CVE-2017-6838MEDIUM Integer overflow in sfcommands/sfconvert.c in Audio File Library (aka audiofile) 0.3.6 allows remote attackers to cause a denial of service (crash) via a crafted file. | Mar 20, 2017 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Audiofile.
Media articles that mention a CVE ID that affects a product developed by Audiofile — matched by CVE ID, not by vendor name.