← Vulnerability feed

Vulnerability record · CVE-2003-0865 · published 17 November 2003

CVE-2003-0865: Mpg123 vulnerability

Mpg123 · Mpg123

Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.

7.5 CVSS 2.0 High EPSS 15% · top 3.5%
7.5CVSS 2.0 base score
15%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in readstring of httpget.c for mpg123 0.59r and 0.59s allows remote attackers to execute arbitrary code via a long request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2003-0865 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1301Mpg123 vulnerabilityInteger signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service…EPSS 5.4%10.0CVE-2004-0982Mpg123 vulnerabilityBuffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execut…EPSS 6.5%10.0CVE-2004-1284Mpg123 vulnerabilityBuffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 pla…EPSS 14%8.3CVE-2017-12839Mpg123 out-of-bounds read vulnerabilityA heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible…EPSS 2.9%7.5CVE-2014-9497Mpg123 memory buffer overflow vulnerabilityBuffer overflow in mpg123 before 1.18.0.EPSS 2.3%7.5CVE-2017-10683Mpg123 out-of-bounds read vulnerabilityIn mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote den…EPSS 1.2%7.5CVE-2006-3355Mpg123 vulnerabilityHeap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not pr…EPSS 6.5%7.5CVE-2004-0991Mpg123 vulnerabilityBuffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2003-0865), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.