libsndfile_project CVE Vulnerabilities & Metrics

Focus on libsndfile_project vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About libsndfile_project Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with libsndfile_project. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total libsndfile_project CVEs: 29
Earliest CVE date: 16 Jan 2015, 16:59 UTC
Latest CVE date: 27 Oct 2024, 22:15 UTC

Latest CVE reference: CVE-2024-50613

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 2

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical libsndfile_project CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.23

Max CVSS: 7.5

Critical CVEs (≥9): 0

CVSS Range vs. Count

Range Count
0.0-3.9 6
4.0-6.9 22
7.0-8.9 1
9.0-10.0 0

CVSS Distribution Chart

Top 5 Highest CVSS libsndfile_project CVEs

These are the five CVEs with the highest CVSS scores for libsndfile_project, sorted by severity first and recency.

All CVEs for libsndfile_project

libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.

libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.

Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.

CVE-2021-4156 libsndfile_project vulnerability CVSS: 5.8 23 Mar 2022, 20:15 UTC

An out-of-bounds read flaw was found in libsndfile's FLAC codec functionality. An attacker who is able to submit a specially crafted file (via tricking a user to open or otherwise) to an application linked with libsndfile and using the FLAC codec, could trigger an out-of-bounds read that would most likely cause a crash but could potentially leak memory information that could be used in further exploitation of other flaws.

CVE-2021-3246 libsndfile_project vulnerability CVSS: 6.8 20 Jul 2021, 15:15 UTC

A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.

CVE-2019-3832 libsndfile_project vulnerability CVSS: 1.9 21 Mar 2019, 16:01 UTC

It was discovered the fix for CVE-2018-19758 (libsndfile) was not complete and still allows a read beyond the limits of a buffer in wav_write_header() function in wav.c. A local attacker may use this flaw to make the application crash.

CVE-2018-19758 libsndfile_project vulnerability CVSS: 4.3 30 Nov 2018, 03:29 UTC

There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.

CVE-2018-19662 libsndfile_project vulnerability CVSS: 5.8 29 Nov 2018, 08:29 UTC

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.

CVE-2018-19661 libsndfile_project vulnerability CVSS: 4.3 29 Nov 2018, 08:29 UTC

An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.

CVE-2018-19432 libsndfile_project vulnerability CVSS: 4.3 22 Nov 2018, 05:29 UTC

An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.

CVE-2018-13419 libsndfile_project vulnerability CVSS: 4.3 07 Jul 2018, 17:29 UTC

An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were unable to reproduce and closed the issue

CVE-2018-13139 libsndfile_project vulnerability CVSS: 6.8 04 Jul 2018, 14:29 UTC

A stack-based buffer overflow in psf_memset in common.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted audio file. The vulnerability can be triggered by the executable sndfile-deinterleave.

CVE-2017-16942 libsndfile_project vulnerability CVSS: 4.3 25 Nov 2017, 17:29 UTC

In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio file.

CVE-2017-14246 libsndfile_project vulnerability CVSS: 5.8 21 Sep 2017, 13:29 UTC

An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

CVE-2017-14245 libsndfile_project vulnerability CVSS: 5.8 21 Sep 2017, 13:29 UTC

An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

CVE-2017-14634 libsndfile_project vulnerability CVSS: 4.3 21 Sep 2017, 07:29 UTC

In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.

CVE-2017-12562 libsndfile_project vulnerability CVSS: 7.5 05 Aug 2017, 17:29 UTC

Heap-based Buffer Overflow in the psf_binheader_writef function in common.c in libsndfile through 1.0.28 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

CVE-2017-6892 libsndfile_project vulnerability CVSS: 6.8 12 Jun 2017, 16:29 UTC

In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF file.

CVE-2017-8365 libsndfile_project vulnerability CVSS: 4.3 30 Apr 2017, 19:59 UTC

The i2les_array function in pcm.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted audio file.

CVE-2017-8363 libsndfile_project vulnerability CVSS: 4.3 30 Apr 2017, 19:59 UTC

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted audio file.

CVE-2017-8362 libsndfile_project vulnerability CVSS: 4.3 30 Apr 2017, 19:59 UTC

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (invalid read and application crash) via a crafted audio file.

CVE-2017-8361 libsndfile_project vulnerability CVSS: 6.8 30 Apr 2017, 19:59 UTC

The flac_buffer_copy function in flac.c in libsndfile 1.0.28 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted audio file.

CVE-2017-7742 libsndfile_project vulnerability CVSS: 4.3 12 Apr 2017, 18:59 UTC

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with read memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVE-2017-7741 libsndfile_project vulnerability CVSS: 4.3 12 Apr 2017, 18:59 UTC

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a segmentation violation (with write memory access) via a specially crafted FLAC file during a resample attempt, a similar issue to CVE-2017-7585.

CVE-2017-7586 libsndfile_project vulnerability CVSS: 4.3 07 Apr 2017, 20:59 UTC

In libsndfile before 1.0.28, an error in the "header_read()" function (common.c) when handling ID3 tags can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

CVE-2017-7585 libsndfile_project vulnerability CVSS: 4.3 07 Apr 2017, 20:59 UTC

In libsndfile before 1.0.28, an error in the "flac_buffer_copy()" function (flac.c) can be exploited to cause a stack-based buffer overflow via a specially crafted FLAC file.

CVE-2014-9756 libsndfile_project vulnerability CVSS: 5.0 19 Nov 2015, 20:59 UTC

The psf_fwrite function in file_io.c in libsndfile allows attackers to cause a denial of service (divide-by-zero error and application crash) via unspecified vectors related to the headindex variable.

CVE-2014-9496 libsndfile_project vulnerability CVSS: 2.1 16 Jan 2015, 16:59 UTC

The sd2_parse_rsrc_fork function in sd2.c in libsndfile allows attackers to have unspecified impact via vectors related to a (1) map offset or (2) rsrc marker, which triggers an out-of-bounds read.