Vulnerabilities
Vulnerable Software
Nullsoft:  >> Winamp  >> 3.0  Security Vulnerabilities
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML files that are referenced from XML files contained in a .wsz skin file.
CVSS Score
4.6
EPSS Score
0.043
Published
2004-08-28
Multiple buffer overflows in Winamp 3.0 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a .b4s file containing (1) a long playlist name or (2) a long path in a file: argument to the Playstring parameter.
CVSS Score
9.3
EPSS Score
0.025
Published
2003-12-31
Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters.
CVSS Score
2.1
EPSS Score
0.002
Published
2003-12-31
Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux.
CVSS Score
5.0
EPSS Score
0.007
Published
2003-12-31
The IN_MIDI.DLL plugin 3.01 and earlier, as used in Winamp 2.91, allows remote attackers to execute arbitrary code via a MIDI file with a large "Track data size" value.
CVSS Score
7.5
EPSS Score
0.045
Published
2003-09-17
Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.
CVSS Score
7.5
EPSS Score
0.048
Published
2003-04-02
Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.
CVSS Score
7.5
EPSS Score
0.031
Published
2002-12-26


Contact Us

Shodan ® - All rights reserved