MPlayer is a widely deployed open-source multimedia player with a compact product footprint concentrated on the core player and Unix variant, despite maintaining prominence in the vulnerability landscape. Its disclosures cluster around memory-safety weaknesses, particularly buffer boundary violations and related low-level parsing issues, which arise from its handling of diverse media formats and codecs. Vulnerabilities affecting the vendor frequently acquire public exploit code, reflecting the accessibility of media-parsing attack surfaces and the player's role in processing untrusted content from varied sources. Defenders should treat MPlayer's advisories as relevant wherever the player processes downloaded or network-sourced media and prioritize updates for exposed playback environments; live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mplayer over time
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-0386HIGH Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header. | May 4, 2004 | 10.0 | 49 | NO | YES |
CVE-2008-1558HIGH Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a | Mar 31, 2008 | 10.0 | 45 | NO | YES |
CVE-2004-0659HIGH Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name. | Aug 6, 2004 | 10.0 | 42 | NO | YES |
CVE-2008-0485HIGH Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom | Feb 5, 2008 | 9.3 | 37 | NO | YES |
CVE-2007-4938HIGH Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbi | Sep 18, 2007 | 7.6 | 36 | NO | YES |
CVE-2004-1285HIGH Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream. | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2004-1309HIGH Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containi | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2004-1310HIGH Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet. | Jan 10, 2005 | 10.0 | 32 | NO | NO |
CVE-2008-4610MEDIUM MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) fi | Oct 20, 2008 | 5.0 | 30 | NO | YES |
CVE-2004-1188HIGH The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREA | Jan 10, 2005 | 10.0 | 30 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mplayer.
Media articles that mention a CVE ID that affects a product developed by Mplayer — matched by CVE ID, not by vendor name.