Mpg321 Project develops a lightweight audio player for MP3 files and operates within a niche but established ecosystem of command-line audio tools. The project's vulnerability history centers on its core mpg321 player and has surfaced memory-safety issues including out-of-bounds write conditions. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mpg321 Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2002-0272HIGH Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3 | May 31, 2002 | 10.0 | 26 | NO | NO |
CVE-2019-14247MEDIUM The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file. | Jul 24, 2019 | 5.5 | 21 | NO | NO |
CVE-2003-0969HIGH mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggerin | Jan 20, 2004 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mpg321 Project.
Media articles that mention a CVE ID that affects a product developed by Mpg321 Project — matched by CVE ID, not by vendor name.