Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.249
EPSS Ranking 95.9%