Skip to main content

Vendor/product archive

libsndfile_project / libsndfile CVEs

Beta · best-effort

32 CVEs tagged to libsndfile_project / libsndfile1 Critical, 12 High, 18 Medium, 1 Low, 0 Unrated.

CVE-2026-37555

Published Apr 29, 2026

An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. The AIFF code path (line 241) was fixed with (sf_count_t) cast, but the WAV code path (line 235) and close path (line…

CVSS 7.5 · High
evidence mentions
21
Buzz score
49.5
Vendor/product tagsBeta · best-effort

CVE-2025-56226

Published Jan 14, 2026

Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file.

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-52194

Published Aug 21, 2025

A buffer overflow vulnerability exists in libsndfile version 1.2.2 and potentially earlier versions when processing malformed IRCAM audio files. The vulnerability occurs in the ir…

CVSS 7.5 · High
evidence mentions
3
Buzz score
28.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2022-33065

Published Jul 18, 2023

Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause D…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33064

Published Jul 18, 2023

An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Se…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-13419

Published Jul 7, 2018

An issue has been found in libsndfile 1.0.28. There is a memory leak in psf_allocate in common.c, as demonstrated by sndfile-convert. NOTE: The maintainer and third parties were u…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-16942

Published Nov 25, 2017

In libsndfile 1.0.25 (fixed in 1.0.26), a divide-by-zero error exists in the function wav_w64_read_fmt_chunk() in wav_w64.c, which may lead to DoS when playing a crafted audio fil…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2017-6892

Published Jun 12, 2017

In libsndfile version 1.0.28, an error in the "aiff_read_chanmap()" function (aiff.c) can be exploited to cause an out-of-bounds read memory access via a specially crafted AIFF fi…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 32 CVEsPage 1 of 2