Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mpg123 HIGH 8.3
CVE-2017-12839

A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible…

Fix: after 1.25.5
Fix from $1,950 2019-05-09
Mpg123 HIGH 7.5
CVE-2014-9497

Buffer overflow in mpg123 before 1.18.0.

Fix: after 1.17.0
Fix from $1,950 2017-08-29
Mpg123 MEDIUM 5.5
CVE-2017-12797

Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers to cause …

Fix: after 1.25.4
Fix from $1,600 2017-08-29
Mpg123 MEDIUM 5.5
CVE-2017-9545

The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a crafted …

No fix yet
Fix from $1,600 2017-07-27
Mpg123 MEDIUM 5.5
CVE-2017-11126

The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-read and a…

Fix: after 1.25.1
Fix from $1,600 2017-07-10
Mpg123 HIGH 7.5
CVE-2017-10683

In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote den…

Mitigation only
Fix from $1,950 2017-06-29
Mpg123 HIGH 10.0
CVE-2009-1301EPSS 5%

Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service…

Fix: after 1.7.1
Fix from $1,950 2009-04-16
Mpg123 HIGH 7.5
CVE-2006-3355EPSS 7%

Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not pr…

Patch available
Fix from $1,950 2006-07-06
Mpg123 MEDIUM 6.5
CVE-2006-1655

Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via a certain…

No fix yet
Fix from $1,600 2006-04-06
Mpg123 HIGH 10.0
CVE-2004-0982EPSS 7%

Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execut…

Patch available
Fix from $1,950 2005-02-09
Mpg123 HIGH 7.5
CVE-2004-0991

Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.

Patch available
Fix from $1,950 2005-01-11
Mpg123 HIGH 10.0
CVE-2004-1284EPSS 14%

Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 pla…

No fix yet
Fix from $1,950 2005-01-10
Mpg123 HIGH 7.5
CVE-2004-0805

Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) …

Patch available
Fix from $1,950 2004-12-23
Mpg123 HIGH 7.5
CVE-2003-0865EPSS 14%

Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.

Patch available
Fix from $1,950 2003-11-17
Mpg123 HIGH 7.5
CVE-2003-0577

mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, which crea…

Patch available
Fix from $1,950 2003-08-18