Libsndfile

Vendor:

First CVE: Jan 16, 2015 · Active for 11 years

32
Total CVEs
More Total CVEs than 96% of tracked products
3.2
Avg CVEs / Year
Higher CVE frequency than 81% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libsndfile over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 16, 2015
11 years ago
Most Recent CVE
Apr 29, 2026
89 days ago

CVE Severity & Scoring

Libsndfile32 CVEs
All CVEs352,727 CVEs
LowMediumHighCritical
Attack Vector
Local8 (25.0%)
Network22 (68.8%)
Unknown2 (6.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low30 (93.8%)
High0 (0.0%)
Unknown2 (6.3%)
User Interaction
None5 (15.6%)
Unknown2 (6.3%)
Required25 (78.1%)
Privileges Required
Low1 (3.1%)
High0 (0.0%)
None29 (90.6%)
Unknown2 (6.3%)

Top CVEs

Signals from CVEs in this product scope (32 CVEs).

32 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line 1
Apr 29, 20268.235NONO
Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or
Aug 5, 20179.833NONO
The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecifi
Apr 30, 20178.830NONO
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
Jul 20, 20218.829NONO
In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF fil
Jun 12, 20178.829NONO
A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified o
Jul 4, 20188.827NONO
An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and
Sep 21, 20178.127NONO
An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and
Sep 21, 20178.127NONO
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
Nov 29, 20188.126NONO
A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the irc
Aug 21, 20257.525NONO

Exploit Exposure

Signals from CVEs in this product scope (32 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (32 CVEs).

Media Mentions

Signals from CVEs in this product scope (32 CVEs).

Top CNAs Publishing CVEs For Libsndfile

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.2.218.20.5%00
1.1.1017.11.8%00
1.1.017.80.3%00
1.0.3018.83.3%00
1.0.28167.42.6%00
1.0.2516.51.2%00