Show filters
75 Total Results
Displaying 31-40 of 75
Sort by:
Attacker Value
Unknown
CVE-2008-3567
Disclosure Date: August 10, 2008 (last updated October 04, 2023)
Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags.
0
Attacker Value
Unknown
CVE-2008-3441
Disclosure Date: August 01, 2008 (last updated October 04, 2023)
Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning.
0
Attacker Value
Unknown
CVE-2008-0065
Disclosure Date: January 22, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.
0
Attacker Value
Unknown
CVE-2007-6403
Disclosure Date: December 17, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the time of the attack.
0
Attacker Value
Unknown
CVE-2007-4619
Disclosure Date: October 12, 2007 (last updated October 04, 2023)
Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2007-4403
Disclosure Date: August 18, 2007 (last updated October 04, 2023)
The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file.
0
Attacker Value
Unknown
CVE-2007-4392
Disclosure Date: August 17, 2007 (last updated October 04, 2023)
Winamp 5.35 allows remote attackers to cause a denial of service (program stack overflow and application crash) via an M3U file that recursively includes itself.
0
Attacker Value
Unknown
CVE-2007-2498
Disclosure Date: May 04, 2007 (last updated October 04, 2023)
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-2180
Disclosure Date: April 24, 2007 (last updated October 04, 2023)
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.
0
Attacker Value
Unknown
CVE-2007-1922
Disclosure Date: April 10, 2007 (last updated October 04, 2023)
The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption.
0