Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Libsndfile Project

First CVE: Jan 16, 2015Active for: 12 yearsTotal CVEs: 32
34.2
VTI Score
Medium

Libsndfile is a widely embedded audio-file parsing library that, despite maintaining a narrow product scope, occupies a prominent position across multimedia applications, audio processing tools, and media frameworks due to its deep integration into software supply chains. The vendor's vulnerability disclosures cluster around memory-safety and arithmetic weaknesses—out-of-bounds reads and writes, improper buffer-boundary enforcement, divide-by-zero conditions, and integer overflow—that are characteristic of C-based parsers handling untrusted audio file formats. These weakness classes reflect the inherent complexity of safely decoding diverse audio codecs and container formats, and a single flaw can propagate to every downstream application that links the library, amplifying the significance of each disclosure relative to volume. Defenders should prioritize tracking this vendor's updates and inventory applications that embed the library, since remediation typically depends on downstream vendors rebuilding and releasing patched versions; live severity and exploitation figures are shown alongside this summary.

FAUCET AI Generated
32
Total CVEs
More Total CVEs than 97% of tracked vendors
3.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 94% of tracked vendors
6.8
Avg CVSS Score
Higher Avg CVSS Score than 47% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Libsndfile Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2015
11 years ago
Most Recent CVE
Apr 29, 2026
86 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-37555HIGH
An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 1
Apr 29, 20268.235NONO
CVE-2017-12562CRITICAL
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or
Aug 5, 20179.833NONO
CVE-2017-8361HIGH
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecifi
Apr 30, 20178.830NONO
CVE-2021-3246HIGH
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
Jul 20, 20218.829NONO
CVE-2017-6892HIGH
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF fil
Jun 12, 20178.829NONO
CVE-2018-13139HIGH
A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified o
Jul 4, 20188.827NONO
CVE-2017-14246HIGH
An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and
Sep 21, 20178.127NONO
CVE-2017-14245HIGH
An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and
Sep 21, 20178.127NONO
CVE-2018-19662HIGH
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
Nov 29, 20188.126NONO
CVE-2025-52194HIGH
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the irc
Aug 21, 20257.525NONO
View all 32 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products32 CVEs
56%
38%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local8 (25.0%)
Network22 (68.8%)
Unknown2 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (93.8%)
High0 (0.0%)
Unknown2 (6.3%)
User Interaction
None5 (15.6%)
Unknown2 (6.3%)
Required25 (78.1%)
Privileges Required
Low1 (3.1%)
High0 (0.0%)
None29 (90.6%)
Unknown2 (6.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Libsndfile Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Libsndfile Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Libsndfile Project's Products

View all 2 CNAs →

Top CWEs