The Lame Project maintains a focused vulnerability footprint centered on its single, narrowly scoped product, though the project's presence in the vulnerability landscape is more prominent than typical of its product breadth. Vulnerabilities affecting the project tend toward memory-safety and bounds-checking weaknesses such as buffer-boundary violations, out-of-bounds reads, NULL-pointer dereferences, and divide-by-zero conditions, and frequently acquire public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lame Project over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-9872HIGH The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack- | Jun 25, 2017 | 7.8 | 41 | NO | YES |
CVE-2017-9869MEDIUM The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read | Jun 25, 2017 | 5.5 | 32 | NO | YES |
CVE-2017-9412MEDIUM The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a craft | Jul 27, 2017 | 5.5 | 31 | NO | YES |
CVE-2017-11720CRITICAL There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file. | Jul 28, 2017 | 9.8 | 30 | NO | NO |
CVE-2017-8419HIGH LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overfl | May 2, 2017 | 7.8 | 25 | NO | NO |
CVE-2017-13712HIGH NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argume | Aug 28, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-9871HIGH The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buf | Jun 25, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-15019HIGH LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call. | Oct 5, 2017 | 7.8 | 23 | NO | NO |
CVE-2015-9100MEDIUM The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via | Jun 25, 2017 | 5.5 | 21 | NO | NO |
CVE-2017-15046MEDIUM LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412. | Oct 6, 2017 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lame Project.
Media articles that mention a CVE ID that affects a product developed by Lame Project — matched by CVE ID, not by vendor name.