The Libmp3splt Project maintains a focused audio-processing library designed for splitting MP3 and Ogg files, which, despite its narrow scope, sees embedding in media applications and tools that parse untrusted audio input. Its observed vulnerability profile centers on input-validation and NULL-pointer-dereference flaws characteristic of audio codec parsers handling malformed or crafted media files. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Libmp3splt Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5665MEDIUM The splt_cue_export_to_file function in cue.c in libmp3splt 0.9.2 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted file. | Mar 1, 2017 | 5.5 | 20 | NO | NO |
CVE-2017-15185MEDIUM plugins/ogg.c in Libmp3splt 0.9.2 calls the libvorbis vorbis_block_clear function with uninitialized data upon detection of invalid input, which allows remote attackers to cause a | Oct 9, 2017 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Libmp3splt Project.
Media articles that mention a CVE ID that affects a product developed by Libmp3splt Project — matched by CVE ID, not by vendor name.