Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-0476Improper Restriction of Operations within the Bounds of a Memory Buffer in Winamp

11 documents4 sources
Severity
9.3CRITICALNVD
NVD7.6
EPSS
88.6%
top 0.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJan 31
Latest updateMay 1

Description

Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Affected Packages1 packages

NVDnullsoft/winamp18 versions+17

Patches

🔴Vulnerability Details

3
GHSA
GHSA-249v-jf5r-cp5r: Multiple buffer overflows in NullSoft Winamp 52022-05-01
GHSA
GHSA-jv33-3xgx-xjg2: Buffer overflow in Nullsoft Winamp 52022-05-01
GHSA
GHSA-8jv5-qc9q-5qfw: Buffer overflow in Nullsoft Winamp 52022-05-01

💥Exploits & PoCs

5
Exploit-DB
Winamp - Playlist UNC Path Computer Name Overflow (Metasploit)2010-04-30
Exploit-DB
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)2007-03-07
Exploit-DB
Winamp 5.12 - '.pls' Remote Buffer Overflow (Metasploit)2006-01-31
Exploit-DB
Winamp 5.12 - '.pls' Remote Buffer Overflow (1)2006-01-29
Metasploit
Winamp Playlist UNC Path Computer Name Overflow