mpv records
3 published records for vendor mpv.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-134 Use of Externally-Controlled Format String1
- CWE-20 Improper Input Validation1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-6360No exploit | mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDEmpv · mpv · CWE-20 | High8.8 | — | 2.6% | Jan 27, 2018 |
32Monitor | CVE-2021-30145No exploit | A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playlimpv · mpv · CWE-134 | High7.8 | — | 2.4% | May 18, 2021 |
28Monitor | CVE-2020-19824No exploit | An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.mpv · mpv · CWE-362 | High7.0 | — | 0.2% | Feb 17, 2023 |
- CVE-2018-636036Monitor
mpv through 0.28.0 allows remote attackers to execute arbitrary code via a crafted web site, because it reads HTML documents containing VIDE
HighCVSS 8.8No exploitEPSS 3%mpv · mpvJan 27, 2018
- CVE-2021-3014532Monitor
A format string vulnerability in mpv through 0.33.0 allows user-assisted remote attackers to achieve code execution via a crafted m3u playli
HighCVSS 7.8No exploitEPSS 2%mpv · mpvMay 18, 2021
- CVE-2020-1982428Monitor
An issue in MPV v.0.29.1 fixed in v0.30 allows attackers to execute arbitrary code and crash program via the ao_c parameter.
HighCVSS 7.0No exploitEPSS 0%mpv · mpvFeb 17, 2023