Vulnerabilities > Mpg123 > Mpg123 > 0.59n

DATE CVE VULNERABILITY TITLE RISK
2009-04-16 CVE-2009-1301 Numeric Errors vulnerability in Mpg123
Integer signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service (out-of-bounds memory access) and possibly execute arbitrary code via an ID3 tag with a negative encoding value.
network
low complexity
mpg123 CWE-189
critical
10.0
2007-01-30 CVE-2007-0578 Denial of Service vulnerability in MPG123 HTTP_Open() Connection Handling
The http_open function in httpget.c in mpg123 before 0.64 allows remote attackers to cause a denial of service (infinite loop) by closing the HTTP connection early.
network
mpg123
4.3
2005-01-11 CVE-2004-0991 Heap Overflow vulnerability in MPG123 Layer 2 Frame Header
Buffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.
network
low complexity
mpg123 suse
7.5
2005-01-10 CVE-2004-1284 Unspecified vulnerability in Mpg123
Buffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 playlist.
network
low complexity
mpg123
critical
10.0