Musicpd is a lightweight, daemon-based music player designed for server and embedded deployments, with its vulnerability profile centered on the core Music Player Daemon application. The observed weakness classes—out-of-bounds writes and reachable assertions—reflect the input-parsing and memory-handling demands of an audio-processing service; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Musicpd over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-48363HIGH In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eve | Feb 26, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-46449HIGH An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input. | Jan 10, 2023 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Musicpd.
Media articles that mention a CVE ID that affects a product developed by Musicpd — matched by CVE ID, not by vendor name.