Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mplayer

First CVE: Nov 17, 2003Active for: 23 yearsTotal CVEs: 33
63.1
VTI Score
TOP TARGET

MPlayer is a widely deployed open-source multimedia player with a compact product footprint concentrated on the core player and Unix variant, despite maintaining prominence in the vulnerability landscape. Its disclosures cluster around memory-safety weaknesses, particularly buffer boundary violations and related low-level parsing issues, which arise from its handling of diverse media formats and codecs. Vulnerabilities affecting the vendor frequently acquire public exploit code, reflecting the accessibility of media-parsing attack surfaces and the player's role in processing untrusted content from varied sources. Defenders should treat MPlayer's advisories as relevant wherever the player processes downloaded or network-sourced media and prioritize updates for exposed playback environments; live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
2.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
8.4
Avg CVSS Score
Higher Avg CVSS Score than 81% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mplayer over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 17, 2003
22 years ago
Most Recent CVE
May 20, 2011
5,544 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2004-0386HIGH
Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.
May 4, 200410.049NOYES
CVE-2008-1558HIGH
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote attackers to overwrite memory and execute arbitrary code via a
Mar 31, 200810.045NOYES
CVE-2004-0659HIGH
Buffer overflow in TranslateFilename for common.c in MPlayer 1.0pre4 allows remote attackers to execute arbitrary code via a long file name.
Aug 6, 200410.042NOYES
CVE-2008-0485HIGH
Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbitrary code via a QuickTime MOV file with a crafted stsc atom
Feb 5, 20089.337NOYES
CVE-2007-4938HIGH
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to cause a denial of service (application crash) or possibly execute arbi
Sep 18, 20077.636NOYES
CVE-2004-1285HIGH
Buffer overflow in the get_header function in asf_mmst_streaming.c for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a crafted ASF video stream.
Jan 10, 200510.032NONO
CVE-2004-1309HIGH
Heap-based buffer overflow in the demux_open_bmp function in demux_bmp.c for Unix MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a bitmap (BMP) file containi
Jan 10, 200510.032NONO
CVE-2004-1310HIGH
Stack-based buffer overflow in the asf_mmst_streaming.c functionality for MPlayer 1.0pre5 allows remote attackers to execute arbitrary code via a large MMST stream packet.
Jan 10, 200510.032NONO
CVE-2008-4610MEDIUM
MPlayer allows remote attackers to cause a denial of service (application crash) via (1) a malformed AAC file, as demonstrated by lol-vlc.aac; or (2) a malformed Ogg Media (OGM) fi
Oct 20, 20085.030NOYES
CVE-2004-1188HIGH
The pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the chunk size is less than the PREA
Jan 10, 200510.030NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
21%
79%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown33 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown33 (100.0%)
User Interaction
None0 (0.0%)
Unknown33 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown33 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
21.2% of CVEs· 78th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mplayer.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mplayer — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mplayer's Products

View all 3 CNAs →

Top CWEs