Symonics develops libmysofa, a specialized audio signal-processing library for handling SOFA (Spatially Oriented Format for Acoustics) files, which sits in the audio software supply chain and is embedded across professional audio workstations, spatial audio engines, and acoustic simulation tools. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses, including out-of-bounds reads and writes, NULL-pointer dereferences, and classic buffer overflows that are characteristic of C-based signal-processing code handling untrusted audio metadata. Defenders should inventory products that link this library and prioritize remediation of its advisories; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Symonics over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3756CRITICAL libmysofa is vulnerable to Heap-based Buffer Overflow | Oct 29, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-16093CRITICAL Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c. | Sep 8, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-16092CRITICAL Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c. | Sep 8, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-10672CRITICAL treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions. | Mar 31, 2019 | 9.8 | 30 | NO | NO |
CVE-2019-20063HIGH hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json. | Dec 29, 2019 | 8.8 | 27 | NO | NO |
CVE-2020-36152HIGH Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA. | Feb 8, 2021 | 8.8 | 25 | NO | NO |
CVE-2019-16091HIGH Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c. | Sep 8, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-16095HIGH Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c. | Sep 8, 2019 | 7.5 | 24 | NO | NO |
CVE-2019-16094HIGH Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c. | Sep 8, 2019 | 7.5 | 24 | NO | NO |
CVE-2020-6860HIGH libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute. | Jan 13, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Symonics.
Media articles that mention a CVE ID that affects a product developed by Symonics — matched by CVE ID, not by vendor name.