Glensawyer maintains MP3Gain, an audio-processing utility that manipulates MP3 file metadata and encoding, with a focused vulnerability footprint centered on buffer-handling flaws in parsing and format processing. The recurring weakness classes—out-of-bounds reads and writes—reflect the memory-safety demands of direct binary audio-file manipulation; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Glensawyer over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-34085CRITICAL Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application cras | May 11, 2022 | 9.8 | 31 | NO | NO |
CVE-2023-49356HIGH A stack buffer overflow vulnerability in MP3Gain v1.6.2 allows an attacker to cause a denial of service via the WriteMP3GainAPETag function at apetag.c:592. | Dec 22, 2023 | 7.5 | 21 | NO | NO |
CVE-2019-18359MEDIUM A buffer over-read was discovered in ReadMP3APETag in apetag.c in MP3Gain 1.6.2. The vulnerability causes an application crash, which leads to remote denial of service. | Oct 23, 2019 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Glensawyer.
Media articles that mention a CVE ID that affects a product developed by Glensawyer — matched by CVE ID, not by vendor name.