mplayerhq CVE Vulnerabilities & Metrics

Focus on mplayerhq vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About mplayerhq Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with mplayerhq. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total mplayerhq CVEs: 15
Earliest CVE date: 30 Sep 2010, 15:00 UTC
Latest CVE date: 15 Sep 2022, 16:15 UTC

Latest CVE reference: CVE-2022-38851

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): 0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): 0.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical mplayerhq CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 2.2

Max CVSS: 10.0

Critical CVEs (≥9): 2

CVSS Range vs. Count

Range Count
0.0-3.9 14
4.0-6.9 4
7.0-8.9 0
9.0-10.0 2

CVSS Distribution Chart

Top 5 Highest CVSS mplayerhq CVEs

These are the five CVEs with the highest CVSS scores for mplayerhq, sorted by severity first and recency.

All CVEs for mplayerhq

CVE-2022-38851 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 16:15 UTC

Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38850 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 16:15 UTC

The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c.

CVE-2022-38600 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 16:15 UTC

Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c.

CVE-2022-38866 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38865 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38864 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVE-2022-38863 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.

CVE-2022-38862 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38861 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.

CVE-2022-38860 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38858 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38856 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38855 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-38853 mplayerhq vulnerability CVSS: 0 15 Sep 2022, 15:15 UTC

Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.

CVE-2022-32317 mplayerhq vulnerability CVSS: 4.3 14 Jul 2022, 20:15 UTC

The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vo_v4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call. Note: This has been disputed by third parties as invalid and not reproduceable.

CVE-2011-2162 mplayerhq vulnerability CVSS: 10.0 20 May 2011, 22:55 UTC

Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."

CVE-2011-2160 mplayerhq vulnerability CVSS: 9.3 20 May 2011, 22:55 UTC

The VC-1 decoding functionality in FFmpeg before 0.5.4, as used in MPlayer and other products, does not properly restrict read operations, which allows remote attackers to have an unspecified impact via a crafted VC-1 file, a related issue to CVE-2011-0723.

CVE-2011-0722 mplayerhq vulnerability CVSS: 6.8 20 May 2011, 22:55 UTC

FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a malformed RealMedia file.

CVE-2010-3908 mplayerhq vulnerability CVSS: 6.8 20 May 2011, 22:55 UTC

FFmpeg before 0.5.4, as used in MPlayer and other products, allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a malformed WMV file.

CVE-2010-3429 mplayerhq vulnerability CVSS: 6.8 30 Sep 2010, 15:00 UTC

flicvideo.c in libavcodec 0.6 and earlier in FFmpeg, as used in MPlayer and other products, allows remote attackers to execute arbitrary code via a crafted flic file, related to an "arbitrary offset dereference vulnerability."