Mpg123 is a command-line audio decoder and player that, despite its narrow product scope, occupies a moderately prominent position in the vulnerability landscape owing to its widespread integration into multimedia frameworks and embedded systems. The vendor's disclosed vulnerabilities recur through memory-safety weakness classes including out-of-bounds reads, buffer-boundary violations, and integer overflow conditions that are typical of audio parsing codebases, and the exposure tends to acquire public exploit tooling. Defenders should monitor this vendor's releases for deployments that expose the decoder to untrusted audio sources; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpg123 over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1284HIGH Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist. | Jan 10, 2005 | 10.0 | 49 | NO | YES |
CVE-2003-0865HIGH Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request. | Nov 17, 2003 | 7.5 | 35 | NO | YES |
CVE-2006-3355HIGH Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not properly terminated before being | Jul 6, 2006 | 7.5 | 30 | NO | YES |
CVE-2009-1301HIGH Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) | Apr 16, 2009 | 10.0 | 28 | NO | NO |
CVE-2004-0982HIGH Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execute arbitrary code via an mp3 fil | Feb 9, 2005 | 10.0 | 27 | NO | NO |
CVE-2004-0991HIGH Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files. | Jan 11, 2005 | 7.5 | 25 | NO | NO |
CVE-2017-10683HIGH In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote denial of service attack. | Jun 29, 2017 | 7.5 | 24 | NO | NO |
CVE-2017-12839HIGH A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible denial-of-service (out-of-boun | May 9, 2019 | 8.3 | 22 | NO | NO |
CVE-2014-9497HIGH Buffer overflow in mpg123 before 1.18.0. | Aug 29, 2017 | 7.5 | 20 | NO | NO |
CVE-2004-0805HIGH Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) mp2 file. | Dec 23, 2004 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpg123.
Media articles that mention a CVE ID that affects a product developed by Mpg123 — matched by CVE ID, not by vendor name.