Vulnerability Details CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.525
EPSS Ranking 97.8%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2013-4694
-
cpe:2.3:a:nullsoft:winamp:0.20a
-
cpe:2.3:a:nullsoft:winamp:0.92
-
cpe:2.3:a:nullsoft:winamp:1.006
-
cpe:2.3:a:nullsoft:winamp:1.90
-
cpe:2.3:a:nullsoft:winamp:2.0
-
cpe:2.3:a:nullsoft:winamp:2.10
-
cpe:2.3:a:nullsoft:winamp:2.6
-
cpe:2.3:a:nullsoft:winamp:2.9
-
cpe:2.3:a:nullsoft:winamp:2.91
-
cpe:2.3:a:nullsoft:winamp:2.92
-
cpe:2.3:a:nullsoft:winamp:2.95
-
cpe:2.3:a:nullsoft:winamp:5.0
-
cpe:2.3:a:nullsoft:winamp:5.01
-
cpe:2.3:a:nullsoft:winamp:5.02
-
cpe:2.3:a:nullsoft:winamp:5.03
-
cpe:2.3:a:nullsoft:winamp:5.04
-
cpe:2.3:a:nullsoft:winamp:5.05
-
cpe:2.3:a:nullsoft:winamp:5.06
-
cpe:2.3:a:nullsoft:winamp:5.07
-
cpe:2.3:a:nullsoft:winamp:5.08c
-
cpe:2.3:a:nullsoft:winamp:5.08d
-
cpe:2.3:a:nullsoft:winamp:5.08e
-
cpe:2.3:a:nullsoft:winamp:5.09
-
cpe:2.3:a:nullsoft:winamp:5.091
-
cpe:2.3:a:nullsoft:winamp:5.093
-
cpe:2.3:a:nullsoft:winamp:5.094
-
cpe:2.3:a:nullsoft:winamp:5.1
-
cpe:2.3:a:nullsoft:winamp:5.11
-
cpe:2.3:a:nullsoft:winamp:5.111
-
cpe:2.3:a:nullsoft:winamp:5.112
-
cpe:2.3:a:nullsoft:winamp:5.12
-
cpe:2.3:a:nullsoft:winamp:5.13
-
cpe:2.3:a:nullsoft:winamp:5.2
-
cpe:2.3:a:nullsoft:winamp:5.21
-
cpe:2.3:a:nullsoft:winamp:5.22
-
cpe:2.3:a:nullsoft:winamp:5.23
-
cpe:2.3:a:nullsoft:winamp:5.24
-
cpe:2.3:a:nullsoft:winamp:5.3
-
cpe:2.3:a:nullsoft:winamp:5.31
-
cpe:2.3:a:nullsoft:winamp:5.32
-
cpe:2.3:a:nullsoft:winamp:5.33
-
cpe:2.3:a:nullsoft:winamp:5.34
-
cpe:2.3:a:nullsoft:winamp:5.35
-
cpe:2.3:a:nullsoft:winamp:5.36
-
cpe:2.3:a:nullsoft:winamp:5.5
-
cpe:2.3:a:nullsoft:winamp:5.51
-
cpe:2.3:a:nullsoft:winamp:5.52
-
cpe:2.3:a:nullsoft:winamp:5.53
-
cpe:2.3:a:nullsoft:winamp:5.531
-
cpe:2.3:a:nullsoft:winamp:5.54
-
cpe:2.3:a:nullsoft:winamp:5.541
-
cpe:2.3:a:nullsoft:winamp:5.55
-
cpe:2.3:a:nullsoft:winamp:5.551
-
cpe:2.3:a:nullsoft:winamp:5.552
-
cpe:2.3:a:nullsoft:winamp:5.56
-
cpe:2.3:a:nullsoft:winamp:5.57
-
cpe:2.3:a:nullsoft:winamp:5.572
-
cpe:2.3:a:nullsoft:winamp:5.58
-
cpe:2.3:a:nullsoft:winamp:5.581
-
cpe:2.3:a:nullsoft:winamp:5.59
-
cpe:2.3:a:nullsoft:winamp:5.61
-
cpe:2.3:a:nullsoft:winamp:5.623
-
cpe:2.3:a:nullsoft:winamp:5.63