Mega Nerd maintains a focused set of audio processing libraries, including libsndfile and Secret Rabbit Code, that serve specialized roles in sound-format handling and sample-rate conversion across embedded and desktop applications. The vendor's vulnerability footprint, while modest in scale, reflects the parsing and signal-processing demands of audio codec implementation. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mega Nerd over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2015-7805HIGH Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file. | Nov 17, 2015 | 9.3 | 41 | NO | YES |
CVE-2009-1788HIGH Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a den | May 26, 2009 | 9.3 | 30 | NO | NO |
CVE-2009-1791HIGH Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a de | May 26, 2009 | 9.3 | 28 | NO | NO |
CVE-2009-0186HIGH Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF au | Mar 5, 2009 | 9.3 | 25 | NO | NO |
CVE-2011-2696MEDIUM Integer overflow in libsndfile before 1.0.25 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PARIS Audio F | Jul 27, 2011 | 6.8 | 24 | NO | NO |
CVE-2008-5008HIGH Buffer overflow in src/src_sinc.c in Secret Rabbit Code (aka SRC or libsamplerate) before 0.1.4, when "extreme low conversion ratios" are used, allows user-assisted attackers to ha | Nov 10, 2008 | 9.3 | 23 | NO | NO |
CVE-2007-4974HIGH Heap-based buffer overflow in the flac_buffer_copy function in libsndfile 1.0.17 and earlier might allow remote attackers to execute arbitrary code via a FLAC file with crafted PCM | Sep 19, 2007 | 7.5 | 21 | NO | NO |
CVE-2009-4835MEDIUM The (1) htk_read_header, (2) alaw_init, (3) ulaw_init, (4) pcm_init, (5) float32_init, and (6) sds_read_header functions in libsndfile 1.0.20 allow context-dependent attackers to c | May 6, 2010 | 4.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mega Nerd.
Media articles that mention a CVE ID that affects a product developed by Mega Nerd — matched by CVE ID, not by vendor name.