Show filters
75 Total Results
Displaying 41-50 of 75
Sort by:
Attacker Value
Unknown

CVE-2007-1921

Disclosure Date: April 10, 2007 (last updated October 04, 2023)
LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT file that contains a value that is used as an offset, which triggers memory corruption.
0
Attacker Value
Unknown

CVE-2006-6547

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Buffer overflow in the readAA function in read_aa.cpp in Winamp iPod Plugin (ml_ipod) 2.00 p19 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long tag in an audible.com audiobook (aa) file.
0
Attacker Value
Unknown

CVE-2006-6539

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Multiple buffer overflows in Winamp Web Interface (Wawi) 7.5.13 and earlier (1) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an (a) long username or a (b) crafted packet to the FindBasicAuth function in security.cpp, related to the /browse URI; and allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via a long path string in the (2) Browse, (3) CControl::Download, and (4) CControl::Load functions, related to the file parameter in the /dl URI. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown

CVE-2006-6513

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function.
0
Attacker Value
Unknown

CVE-2006-6512

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter.
0
Attacker Value
Unknown

CVE-2006-6514

Disclosure Date: December 14, 2006 (last updated October 04, 2023)
Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.
0
Attacker Value
Unknown

CVE-2006-5567

Disclosure Date: October 27, 2006 (last updated October 04, 2023)
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.
0
Attacker Value
Unknown

CVE-2006-3228

Disclosure Date: June 26, 2006 (last updated October 04, 2023)
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.
0
Attacker Value
Unknown

CVE-2006-0720

Disclosure Date: February 23, 2006 (last updated February 22, 2025)
Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.
0
Attacker Value
Unknown

CVE-2006-0708

Disclosure Date: February 15, 2006 (last updated February 22, 2025)
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.
0