MPD (Music Player Daemon) is a lightweight, server-based audio playback application with a narrowly scoped product portfolio, primarily represented by the daemon itself. Its vulnerability exposure centers on memory-safety issues including out-of-bounds reads and writes, reflecting the C-based implementation and audio-codec parsing that characterize the application. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpd Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7465CRITICAL The L2TP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted L2TP control packet with AVP Q.931 Cause Code to execute arbitrary code or caus | Oct 6, 2020 | 9.8 | 30 | NO | NO |
CVE-2020-7466HIGH The PPP implementation of MPD before 5.9 allows a remote attacker who can send specifically crafted PPP authentication message to cause the daemon to read beyond allocated memory b | Oct 6, 2020 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpd Project.
Media articles that mention a CVE ID that affects a product developed by Mpd Project — matched by CVE ID, not by vendor name.