Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Symonics

First CVE: Mar 31, 2019Active for: 7 yearsTotal CVEs: 15
45.8
VTI Score
High

Symonics develops libmysofa, a specialized audio signal-processing library for handling SOFA (Spatially Oriented Format for Acoustics) files, which sits in the audio software supply chain and is embedded across professional audio workstations, spatial audio engines, and acoustic simulation tools. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses, including out-of-bounds reads and writes, NULL-pointer dereferences, and classic buffer overflows that are characteristic of C-based signal-processing code handling untrusted audio metadata. Defenders should inventory products that link this library and prioritize remediation of its advisories; live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
5.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 78% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Symonics over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2019
7 years ago
Most Recent CVE
Oct 29, 2021
1,729 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-3756CRITICAL
libmysofa is vulnerable to Heap-based Buffer Overflow
Oct 29, 20219.831NONO
CVE-2019-16093CRITICAL
Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Sep 8, 20199.831NONO
CVE-2019-16092CRITICAL
Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.
Sep 8, 20199.830NONO
CVE-2019-10672CRITICAL
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
Mar 31, 20199.830NONO
CVE-2019-20063HIGH
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
Dec 29, 20198.827NONO
CVE-2020-36152HIGH
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
Feb 8, 20218.825NONO
CVE-2019-16091HIGH
Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
Sep 8, 20197.525NONO
CVE-2019-16095HIGH
Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
Sep 8, 20197.524NONO
CVE-2019-16094HIGH
Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Sep 8, 20197.524NONO
CVE-2020-6860HIGH
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
Jan 13, 20208.822NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
33%
40%
27%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (46.7%)
Unknown0 (0.0%)
Required8 (53.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Symonics.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Symonics — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Symonics's Products

View all 2 CNAs →

Top CWEs