Записи mpg123
16 опубликованных записей вендора mpg123.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 100 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-125 Out-of-bounds Read4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-189 Numeric Errors1
- CWE-190 Integer Overflow or Wraparound1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
16 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2004-1284Proof of concept | Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a craftempg123 · mpg123 | Критическая10,0 | — | 14,5 % | 10 янв. 2005 г. |
42В плане | CVE-2004-0982Эксплойта нет | Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users mpg123 · mpg123 | Критическая10,0 | — | 6,5 % | 9 февр. 2005 г. |
42В плане | CVE-2009-1301Эксплойта нет | Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial ompg123 · mpg123 · CWE-189 | Критическая10,0 | — | 5,4 % | 16 апр. 2009 г. |
34Наблюдать | CVE-2003-0865Proof of concept | Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a lonmpg123 · mpg123 | Высокая7,5 | — | 14,5 % | 17 нояб. 2003 г. |
34Наблюдать | CVE-2017-12839Эксплойта нет | A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause ampg123 · mpg123 · CWE-125 | Высокая8,3 | — | 2,9 % | 9 мая 2019 г. |
32Наблюдать | CVE-2006-3355Proof of concept | Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which mpg123 · mpg123 | Высокая7,5 | — | 6,5 % | 6 июл. 2006 г. |
31Наблюдать | CVE-2004-0805Эксплойта нет | Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mpmpg123 · mpg123 | Высокая7,5 | — | 3,8 % | 23 дек. 2004 г. |
31Наблюдать | CVE-2003-0577Эксплойта нет | mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, wmpg123 · mpg123 | Высокая7,5 | — | 3,7 % | 18 авг. 2003 г. |
31Наблюдать | CVE-2004-0991Эксплойта нет | Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.mpg123 · mpg123 | Высокая7,5 | — | 3,6 % | 11 янв. 2005 г. |
31Наблюдать | CVE-2014-9497Эксплойта нет | Buffer overflow in mpg123 before 1.18.0.mpg123 · mpg123 · CWE-119 | Высокая7,5 | — | 2,3 % | 29 авг. 2017 г. |
30Наблюдать | CVE-2017-10683Эксплойта нет | In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c.mpg123 · mpg123 · CWE-125 | Высокая7,5 | — | 1,2 % | 29 июн. 2017 г. |
26Наблюдать | CVE-2006-1655Эксплойта нет | Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via mpg123 · mpg123 | Средняя6,5 | — | 1,6 % | 6 апр. 2006 г. |
22Наблюдать | CVE-2017-11126Эксплойта нет | The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-rmpg123 · mpg123 · CWE-125 | Средняя5,5 | — | 1,4 % | 9 июл. 2017 г. |
22Наблюдать | CVE-2017-12797Эксплойта нет | Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers mpg123 · mpg123 · CWE-190 | Средняя5,5 | — | 1,2 % | 29 авг. 2017 г. |
22Наблюдать | CVE-2017-9545Эксплойта нет | The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via ampg123 · mpg123 · CWE-125 | Средняя5,5 | — | 1,2 % | 27 июл. 2017 г. |
17Наблюдать | CVE-2007-0578Эксплойта нет | The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing thmpg123 · mpg123 | Средняя4,3 | — | 1,5 % | 30 янв. 2007 г. |
- CVE-2004-128444В плане
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafte
КритическаяCVSS 10,0Proof of conceptEPSS 14 %mpg123 · mpg12310 янв. 2005 г.
- CVE-2004-098242В плане
Buffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users
КритическаяCVSS 10,0Эксплойта нетEPSS 7 %mpg123 · mpg1239 февр. 2005 г.
- CVE-2009-130142В плане
Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial o
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %mpg123 · mpg12316 апр. 2009 г.
- CVE-2003-086534Наблюдать
Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a lon
ВысокаяCVSS 7,5Proof of conceptEPSS 15 %mpg123 · mpg12317 нояб. 2003 г.
- CVE-2017-1283934Наблюдать
A heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a
ВысокаяCVSS 8,3Эксплойта нетEPSS 3 %mpg123 · mpg1239 мая 2019 г.
- CVE-2006-335532Наблюдать
Heap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %mpg123 · mpg1236 июл. 2006 г.
- CVE-2004-080531Наблюдать
Buffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mpg123 · mpg12323 дек. 2004 г.
- CVE-2003-057731Наблюдать
mpg123 0.59r allows remote attackers to cause a denial of service and possibly execute arbitrary code via an MP3 file with a zero bitrate, w
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mpg123 · mpg12318 авг. 2003 г.
- CVE-2004-099131Наблюдать
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mpg123 · mpg12311 янв. 2005 г.
- CVE-2014-949731Наблюдать
Buffer overflow in mpg123 before 1.18.0.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mpg123 · mpg12329 авг. 2017 г.
- CVE-2017-1068330Наблюдать
In mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %mpg123 · mpg12329 июн. 2017 г.
- CVE-2006-165526Наблюдать
Multiple buffer overflows in mpg123 0.59r allow user-assisted attackers to trigger a segmentation fault and possibly have other impacts via
СредняяCVSS 6,5Эксплойта нетEPSS 2 %mpg123 · mpg1236 апр. 2006 г.
- CVE-2017-1112622Наблюдать
The III_i_stereo function in libmpg123/layer3.c in mpg123 through 1.25.1 allows remote attackers to cause a denial of service (buffer over-r
СредняяCVSS 5,5Эксплойта нетEPSS 1 %mpg123 · mpg1239 июл. 2017 г.
- CVE-2017-1279722Наблюдать
Integer overflow in the INT123_parse_new_id3 function in the ID3 parser in mpg123 before 1.25.5 on 32-bit platforms allows remote attackers
СредняяCVSS 5,5Эксплойта нетEPSS 1 %mpg123 · mpg12329 авг. 2017 г.
- CVE-2017-954522Наблюдать
The next_text function in src/libmpg123/id3.c in mpg123 1.24.0 allows remote attackers to cause a denial of service (buffer over-read) via a
СредняяCVSS 5,5Эксплойта нетEPSS 1 %mpg123 · mpg12327 июл. 2017 г.
- CVE-2007-057817Наблюдать
The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing th
СредняяCVSS 4,3Эксплойта нетEPSS 1 %mpg123 · mpg12330 янв. 2007 г.