Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2006-0720Improper Restriction of Operations within the Bounds of a Memory Buffer in Winamp

3 documents3 sources
Severity
7.6HIGHNVD
EPSS
13.9%
top 5.67%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedFeb 23
Latest updateMay 1

Description

Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file.

CVSS vector

AV:N/AC:H/C:C/I:C/A:CExploitability: 4.9 | Impact: 10.0

Affected Packages1 packages

NVDnullsoft/winamp5.12, 5.13+1

Patches

🔴Vulnerability Details

1
GHSA
GHSA-m734-688v-8r3r: Stack-based buffer overflow in Nullsoft Winamp 52022-05-01

💥Exploits & PoCs

1
Exploit-DB
Winamp 5.12 - '.m3u' Local Stack Buffer Overflow2013-06-17