Mp3gain is a focused audio-processing utility whose vulnerability profile centers on memory-safety issues arising from its handling of MP3 file formats and audio data. The recurring weakness classes—out-of-bounds reads and writes, buffer-boundary violations, input-validation gaps, and NULL-pointer dereferences—reflect the complexity of parsing and manipulating compressed audio streams in a native codebase. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mp3gain over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10778HIGH Read access violation in the III_dequantize_sample function in mpglibDBL/layer3.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application cras | May 7, 2018 | 7.8 | 24 | NO | NO |
CVE-2018-10776HIGH The getbits function in mpglibDBL/common.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (segmentation fault and application crash) or possibly h | May 7, 2018 | 7.8 | 23 | NO | NO |
CVE-2017-14412HIGH An invalid memory write was discovered in copy_mp in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a denial of service (segmentation fault an | Sep 13, 2017 | 7.8 | 22 | NO | NO |
CVE-2017-14411HIGH A stack-based buffer overflow was discovered in copy_mp in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an out-of-bounds write, which leads | Sep 13, 2017 | 7.8 | 22 | NO | NO |
CVE-2017-14409HIGH A buffer overflow was discovered in III_dequantize_sample in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an out-of-bounds write, which leads t | Sep 13, 2017 | 7.8 | 22 | NO | NO |
CVE-2018-10777HIGH Buffer overflow in the WriteMP3GainAPETag function in apetag.c in mp3gain through 1.5.2-r2 allows remote attackers to cause a denial of service (application crash) or possibly have | May 7, 2018 | 7.8 | 20 | NO | NO |
CVE-2017-12911MEDIUM The "apetag.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a stack memory corruption when opening a crafted MP3 file. | Sep 7, 2017 | 5.5 | 19 | NO | NO |
CVE-2017-14408MEDIUM A stack-based buffer over-read was discovered in dct36 in layer3.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to rem | Sep 13, 2017 | 5.5 | 18 | NO | NO |
CVE-2017-14407MEDIUM A stack-based buffer over-read was discovered in filterYule in gain_analysis.c in MP3Gain version 1.5.2. The vulnerability causes an application crash, which leads to remote denial | Sep 13, 2017 | 5.5 | 18 | NO | NO |
CVE-2017-12912MEDIUM The "mpglibDBL/layer3.c" file in MP3Gain 1.5.2.r2 has a vulnerability which results in a read access violation when opening a crafted MP3 file. | Sep 7, 2017 | 5.5 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mp3gain.
Media articles that mention a CVE ID that affects a product developed by Mp3gain — matched by CVE ID, not by vendor name.