Vulnerabilities > Nullsoft > Winamp > 0.92

DATE CVE VULNERABILITY TITLE RISK
2008-08-10 CVE-2008-3567 Cross-Site Scripting vulnerability in Nullsoft Winamp
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
network
nullsoft CWE-79
4.3
2008-08-01 CVE-2008-3441 Code Injection vulnerability in Nullsoft Winamp
Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
network
low complexity
nullsoft CWE-94
7.5
2007-10-12 CVE-2007-4619 Numeric Errors vulnerability in multiple products
Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.
network
flac nullsoft CWE-189
critical
9.3
2006-06-26 CVE-2006-3228 Remote Security vulnerability in Winamp
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.
network
nullsoft
critical
9.3
2005-07-19 CVE-2005-2310 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Nullsoft Winamp
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1) ARTIST or (2) TITLE.
network
nullsoft CWE-119
critical
9.3
2002-07-03 CVE-2002-0547 Buffer Overflow vulnerability in Nullsoft Winamp Minibrowser ID3v2
Buffer overflow in the mini-browser for Winamp 2.79 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field of an ID3v2 tag.
network
low complexity
nullsoft
7.5
2000-07-20 CVE-2000-0624 Unspecified vulnerability in Nullsoft Winamp
Buffer overflow in Winamp 2.64 and earlier allows remote attackers to execute arbitrary commands via a long #EXTINF: extension in the M3U playlist.
network
low complexity
nullsoft
7.5