Mpg321 is a lightweight command-line MP3 player with a narrow vulnerability footprint concentrated in its single core product. The observed weakness classifications reflect parsing and input-handling issues typical of audio-decoding tools. Current vulnerability counts, severity distribution, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpg321 over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0272HIGH Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3 | May 31, 2002 | 10.0 | 26 | NO | NO |
CVE-2019-14247MEDIUM The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file. | Jul 24, 2019 | 5.5 | 21 | NO | NO |
CVE-2003-0969HIGH mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggerin | Jan 20, 2004 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpg321.
Media articles that mention a CVE ID that affects a product developed by Mpg321 — matched by CVE ID, not by vendor name.