Libmysofa

Vendor:

First CVE: Mar 31, 2019 · Active for 7 years

15
Total CVEs
More Total CVEs than 92% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Libmysofa over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 31, 2019
7 years ago
Most Recent CVE
Oct 29, 2021
1,731 days ago

CVE Severity & Scoring

Libmysofa15 CVEs
All CVEs352,719 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network15 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (46.7%)
Unknown0 (0.0%)
Required8 (53.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (100.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
libmysofa is vulnerable to Heap-based Buffer Overflow
Oct 29, 20219.831NONO
Symonics libmysofa 0.7 has an invalid write in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Sep 8, 20199.831NONO
Symonics libmysofa 0.7 has a NULL pointer dereference in getHrtf in hrtf/reader.c.
Sep 8, 20199.830NONO
treeRead in hdf/btree.c in libmysofa before 0.7 does not properly validate multiplications and additions.
Mar 31, 20199.830NONO
hdf/dataobject.c in libmysofa before 0.8 has an uninitialized use of memory, as demonstrated by mysofa2json.
Dec 29, 20198.827NONO
Buffer overflow in readDataVar in hdf/dataobject.c in Symonics libmysofa 0.5 - 1.1 allows attackers to execute arbitrary code via a crafted SOFA.
Feb 8, 20218.825NONO
Symonics libmysofa 0.7 has an out-of-bounds read in directblockRead in hdf/fractalhead.c.
Sep 8, 20197.525NONO
Symonics libmysofa 0.7 has an invalid read in getDimension in hrtf/reader.c.
Sep 8, 20197.524NONO
Symonics libmysofa 0.7 has an invalid read in readOHDRHeaderMessageDataLayout in hdf/dataobject.c.
Sep 8, 20197.524NONO
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
Jan 13, 20208.822NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Libmysofa

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
0.9.118.81.7%00
0.758.41.4%00