← Vulnerability feed

Vulnerability record · CVE-2014-9497 · published 29 August 2017

CVE-2014-9497: Mpg123 memory buffer overflow vulnerability

Mpg123 · Mpg123

Buffer overflow in mpg123 before 1.18.0.

7.5 CVSS 3.0 High EPSS 2.3% · top 17.5% CWE-119 · Memory buffer overflow
7.5CVSS 3.0 base score, v2 5.0
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Buffer overflow in mpg123 before 1.18.0.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-9497 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-1301Mpg123 vulnerabilityInteger signedness error in the store_id3_text function in the ID3v2 code in mpg123 before 1.7.2 allows remote attackers to cause a denial of service…EPSS 5.4%10.0CVE-2004-0982Mpg123 vulnerabilityBuffer overflow in the getauthfromURL function in httpget.c in mpg123 pre0.59s and mpg123 0.59r could allow remote attackers or local users to execut…EPSS 6.5%10.0CVE-2004-1284Mpg123 vulnerabilityBuffer overflow in the find_next_file function in playlist.c for mpg123 0.59r allows remote attackers to execute arbitrary code via a crafted MP3 pla…EPSS 14%8.3CVE-2017-12839Mpg123 out-of-bounds read vulnerabilityA heap-based buffer over-read in the getbits function in src/libmpg123/getbits.h in mpg123 through 1.25.5 allows remote attackers to cause a possible…EPSS 2.9%7.5CVE-2017-10683Mpg123 out-of-bounds read vulnerabilityIn mpg123 1.25.0, there is a heap-based buffer over-read in the convert_latin1 function in libmpg123/id3.c. A crafted input will lead to a remote den…EPSS 1.2%7.5CVE-2006-3355Mpg123 vulnerabilityHeap-based buffer overflow in httpdget.c in mpg123 before 0.59s-rll allows remote attackers to execute arbitrary code via a long URL, which is not pr…EPSS 6.5%7.5CVE-2004-0991Mpg123 vulnerabilityBuffer overflow in mpg123 before 0.59s-r9 allows remote attackers to execute arbitrary code via frame headers in MP2 or MP3 files.EPSS 3.6%7.5CVE-2004-0805Mpg123 vulnerabilityBuffer overflow in layer2.c in mpg123 0.59r and possibly mpg123 0.59s allows remote attackers to execute arbitrary code via a certain (1) mp3 or (2) …EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2014-9497), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.