Vulnerabilities > Nullsoft

DATE CVE VULNERABILITY TITLE RISK
2003-04-02 CVE-2002-1524 Buffer Overflow vulnerability in Nullsoft Winamp 3.0
Buffer overflow in XML parser in wsabi.dll of Winamp 3 (1.0.0.488) allows remote attackers to execute arbitrary code via a skin file (.wal) with a long include file tag.
network
low complexity
nullsoft
7.5
2002-12-31 CVE-2002-2412 Credentials Management vulnerability in Nullsoft Winamp 2.80
Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts.
local
low complexity
nullsoft CWE-255
2.1
2002-12-31 CVE-2002-2392 Unspecified vulnerability in Nullsoft Winamp
Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code.
network
low complexity
nullsoft
6.4
2002-12-31 CVE-2002-2195 Buffer Overflow vulnerability in Nullsoft Winamp Automatic Update Check
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp.com to execute arbitrary code via a long server response.
network
low complexity
nullsoft
5.0
2002-12-26 CVE-2002-1177 Buffer Overrun vulnerability in Nullsoft Winamp 3.0
Multiple buffer overflows in Winamp 3.0, when displaying an MP3 in the Media Library window, allows remote attackers to execute arbitrary code via an MP3 file containing a long (1) Artist or (2) Album ID3v2 tag.
network
low complexity
nullsoft
7.5
2002-12-26 CVE-2002-1176 Remote Security vulnerability in Nullsoft Winamp 2.81
Buffer overflow in Winamp 2.81 allows remote attackers to execute arbitrary code via a long Artist ID3v2 tag in an MP3 file.
network
low complexity
nullsoft
7.5
2002-10-04 CVE-2002-0907 Remote Buffer Overflow vulnerability in Nullsoft Shoutcast Server 1.8.9
Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".
network
low complexity
nullsoft
7.5
2002-07-03 CVE-2002-0547 Buffer Overflow vulnerability in Nullsoft Winamp Minibrowser ID3v2
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag.
network
low complexity
nullsoft
7.5
2002-07-03 CVE-2002-0546 Unspecified vulnerability in Nullsoft Winamp 2.78/2.79
Cross-site scripting vulnerability in the mini-browser for Winamp 2.78 and 2.79 allows remote attackers to execute script via an ID3v1 or ID3v2 tag in an MP3 file.
network
low complexity
nullsoft
7.5
2002-05-31 CVE-2002-0284 Remote Security vulnerability in Nullsoft Winamp 2.77/2.78
Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname.
network
high complexity
nullsoft
2.6