MplayerHQ maintains a focused media-player and transcoding product line centered on MPlayer and MEncoder, tools widely embedded in multimedia workflows and third-party applications despite their narrow official footprint. The vendor's vulnerability disclosures, while modest in volume, concentrate around parser and codec handling, surfacing recurrent weaknesses including out-of-bounds writes, divide-by-zero conditions, buffer-boundary violations, and input-validation gaps that are characteristic of complex media-format processing. These weakness classes reflect the parsing demands of a tool exposed to untrusted media files from diverse sources, where format edge cases and malformed streams can trigger memory corruption or logic errors. Defenders should treat media-player updates as part of supply-chain inventory for any system that processes user-supplied media files or embeds these tools indirectly; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mplayerhq over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-2162HIGH Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (a | May 20, 2011 | 10.0 | 31 | NO | NO |
CVE-2011-2160HIGH The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an | May 20, 2011 | 9.3 | 28 | NO | NO |
CVE-2022-38862HIGH Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2011-0722MEDIUM FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute | May 20, 2011 | 6.8 | 23 | NO | NO |
CVE-2010-3908MEDIUM FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbit | May 20, 2011 | 6.8 | 23 | NO | NO |
CVE-2010-3429MEDIUM flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an | Sep 30, 2010 | 6.8 | 23 | NO | NO |
CVE-2022-38851MEDIUM Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 | Sep 15, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-38600MEDIUM Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c. | Sep 15, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-38866MEDIUM Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38 | Sep 15, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-38865MEDIUM Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and me | Sep 15, 2022 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mplayerhq.
Media articles that mention a CVE ID that affects a product developed by Mplayerhq — matched by CVE ID, not by vendor name.