Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Lame Project

First CVE: May 2, 2017Active for: 9 yearsTotal CVEs: 15
46.0
VTI Score
High

The Lame Project maintains a focused vulnerability footprint centered on its single, narrowly scoped product, though the project's presence in the vulnerability landscape is more prominent than typical of its product breadth. Vulnerabilities affecting the project tend toward memory-safety and bounds-checking weaknesses such as buffer-boundary violations, out-of-bounds reads, NULL-pointer dereferences, and divide-by-zero conditions, and frequently acquire public exploit code. Current severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
15
Total CVEs
More Total CVEs than 94% of tracked vendors
15.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 100% of tracked vendors
6.5
Avg CVSS Score
Higher Avg CVSS Score than 42% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Lame Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 2, 2017
9 years ago
Most Recent CVE
Oct 6, 2017
3,213 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-9872HIGH
The III_dequantize_sample function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-
Jun 25, 20177.841NOYES
CVE-2017-9869MEDIUM
The II_step_one function in layer2.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (buffer over-read
Jun 25, 20175.532NOYES
CVE-2017-9412MEDIUM
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of service (invalid memory read and application crash) via a craft
Jul 27, 20175.531NOYES
CVE-2017-11720CRITICAL
There is a division-by-zero vulnerability in LAME 3.99.5, caused by a malformed input file.
Jul 28, 20179.830NONO
CVE-2017-8419HIGH
LAME through 3.99.5 relies on the signed integer data type for values in a WAV or AIFF header, which allows remote attackers to cause a denial of service (stack-based buffer overfl
May 2, 20177.825NONO
CVE-2017-13712HIGH
NULL Pointer Dereference in the id3v2AddAudioDuration function in libmp3lame/id3tag.c in LAME 3.99.5 allows attackers to perform Denial of Service by triggering a NULL first argume
Aug 28, 20177.524NONO
CVE-2017-9871HIGH
The III_i_stereo function in layer3.c in mpglib, as used in libmpgdecoder.a in LAME 3.99.5 and other products, allows remote attackers to cause a denial of service (stack-based buf
Jun 25, 20177.824NONO
CVE-2017-15019HIGH
LAME 3.99.5 has a NULL Pointer Dereference in the hip_decode_init function within libmp3lame/mpglib_interface.c via a malformed mpg file, because of an incorrect calloc call.
Oct 5, 20177.823NONO
CVE-2015-9100MEDIUM
The fill_buffer_resample function in util.c in libmp3lame.a in LAME 3.99.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via
Jun 25, 20175.521NONO
CVE-2017-15046MEDIUM
LAME 3.99.5, 3.99.4, 3.98.4, 3.98.2, 3.98 and 3.97 have a stack-based buffer overflow in unpack_read_samples in frontend/get_audio.c, a different vulnerability than CVE-2017-9412.
Oct 6, 20175.520NONO
View all 15 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products15 CVEs
60%
33%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local13 (86.7%)
Network2 (13.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None2 (13.3%)
Unknown0 (0.0%)
Required13 (86.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None15 (100.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
20.0% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Lame Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Lame Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Lame Project's Products

View all 1 CNAs →

Top CWEs