Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mpg123

First CVE: Aug 18, 2003Active for: 23 yearsTotal CVEs: 16
57.6
VTI Score
TOP TARGET

Mpg123 is a command-line audio decoder and player that, despite its narrow product scope, occupies a moderately prominent position in the vulnerability landscape owing to its widespread integration into multimedia frameworks and embedded systems. The vendor's disclosed vulnerabilities recur through memory-safety weakness classes including out-of-bounds reads, buffer-boundary violations, and integer overflow conditions that are typical of audio parsing codebases, and the exposure tends to acquire public exploit tooling. Defenders should monitor this vendor's releases for deployments that expose the decoder to untrusted audio sources; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
16
Total CVEs
More Total CVEs than 95% of tracked vendors
2.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 80% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mpg123 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 18, 2003
22 years ago
Most Recent CVE
May 9, 2019
2,633 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (16 CVEs).

16 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-1284HIGH
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
Jan 10, 200510.049NOYES
CVE-2003-0865HIGH
Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.
Nov 17, 20037.535NOYES
CVE-2006-3355HIGH
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being
Jul 6, 20067.530NOYES
CVE-2009-1301HIGH
Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access)
Apr 16, 200910.028NONO
CVE-2004-0982HIGH
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 fil
Feb 9, 200510.027NONO
CVE-2004-0991HIGH
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
Jan 11, 20057.525NONO
CVE-2017-10683HIGH
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack.
Jun 29, 20177.524NONO
CVE-2017-12839HIGH
A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-boun
May 9, 20198.322NONO
CVE-2014-9497HIGH
Buffer overflow in mpg123 before 1.18.0.
Aug 29, 20177.520NONO
CVE-2004-0805HIGH
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file.
Dec 23, 20047.520NONO
View all 16 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products16 CVEs
31%
69%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (18.8%)
Network3 (18.8%)
Unknown10 (62.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (37.5%)
High0 (0.0%)
Unknown10 (62.5%)
User Interaction
None2 (12.5%)
Unknown10 (62.5%)
Required4 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None6 (37.5%)
Unknown10 (62.5%)

Exploit Exposure

Signals from CVEs in this vendor scope (16 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
18.8% of CVEs· 77th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mpg123.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mpg123 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mpg123's Products

View all 1 CNAs →

Top CWEs