CVE-2015-7805: Mega-Nerd Libsndfile

High severity, CVSS 9.3. EPSS: 13.3% chance of exploitation in the next 30 days.

Heap-based buffer overflow in libsndfile 1.0.25 allows remote attackers to have unspecified impact via the headindex value in the header in an AIFF file.

Affected products

  • Mega-Nerd Libsndfile: version 1.0.25 only
  • Opensuse Opensuse: version 13.1 only; version 13.2 only

Published 2015-11-17. Last modified 2026-06-17.