Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mpg321 Project

First CVE: May 31, 2002Active for: 24 yearsTotal CVEs: 3

Mpg321 Project develops a lightweight audio player for MP3 files and operates within a niche but established ecosystem of command-line audio tools. The project's vulnerability history centers on its core mpg321 player and has surfaced memory-safety issues including out-of-bounds write conditions. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
3
Total CVEs
Bottom 1%
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 22% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mpg321 Project over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 31, 2002
24 years ago
Most Recent CVE
Jul 24, 2019
2,557 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (3 CVEs).

3 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2002-0272HIGH
Buffer overflows in mpg321 before 0.2.9 allows local and possibly remote attackers to execute arbitrary code via a long URL to (1) a command line option, (2) an HTTP request, or (3
May 31, 200210.026NONO
CVE-2019-14247MEDIUM
The scan() function in mad.c in mpg321 0.3.2 allows remote attackers to trigger an out-of-bounds write via a zero bitrate in an MP3 file.
Jul 24, 20195.521NONO
CVE-2003-0969HIGH
mpg321 0.2.10 allows remote attackers to overwrite memory and possibly execute arbitrary code via an mp3 file that passes certain strings to the printf function, possibly triggerin
Jan 20, 20047.520NONO
View all 3 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products3 CVEs
33%
67%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (33.3%)
Network0 (0.0%)
Unknown2 (66.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (33.3%)
High0 (0.0%)
Unknown2 (66.7%)
User Interaction
None0 (0.0%)
Unknown2 (66.7%)
Required1 (33.3%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (33.3%)
Unknown2 (66.7%)

Exploit Exposure

Signals from CVEs in this vendor scope (3 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mpg321 Project.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mpg321 Project — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mpg321 Project's Products

View all 1 CNAs →

Top CWEs