Vulnerability index

Browse CVEs

57 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Nullsoft Scriptable Install System HIGH 7.8
CVE-2026-42171

NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attack…

Fix: 3.12+
Fix from $1,950 2026-04-24
Nullsoft Scriptable Install System MEDIUM 5.3
CVE-2023-37378

Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.

Fix: after 3.09
Fix from $1,600 2023-07-03
Winamp HIGH 7.5
CVE-2013-4694EPSS 17%

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possi…

Fix: after 5.63
Fix from $1,950 2014-04-16
Winamp HIGH 7.5
CVE-2012-4045

Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63 build 3235 allow remote attackers to execute arbitrary code via the (1) strf ch…

Fix: after 5.63
Fix from $1,950 2012-07-22
Winamp MEDIUM 6.8
CVE-2012-3889

The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other i…

Fix: after 5.623
Fix from $1,600 2012-07-11
Winamp MEDIUM 6.8
CVE-2012-3890

The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified ot…

Fix: after 5.623
Fix from $1,600 2012-07-11
Winamp HIGH 10.0
CVE-2011-4857

Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message…

Fix: after 5.622
Fix from $1,950 2011-12-16
Winamp HIGH 9.3
CVE-2011-3834EPSS 5%

Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a cr…

Fix: after 5.622
Fix from $1,950 2011-12-16
Winamp HIGH 9.3
CVE-2010-4372

Integer overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allo…

Fix: after 5.581
Fix from $1,950 2010-12-02
Winamp HIGH 9.3
CVE-2010-4370EPSS 5%

Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI file that t…

Fix: after 5.581
Fix from $1,950 2010-12-02
Winamp HIGH 9.3
CVE-2010-4371EPSS 6%

Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment bo…

Fix: after 5.581
Fix from $1,950 2010-12-02
Winamp HIGH 9.3
CVE-2010-2586EPSS 6%

Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Tab…

Fix: after 5.581
Fix from $1,950 2010-12-02
Winamp HIGH 9.3
CVE-2010-1523EPSS 5%

Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to execute arb…

Fix: after 5.581
Fix from $1,950 2010-11-06
Winamp HIGH 9.3
CVE-2010-3137EPSS 8%

Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to exec…

No fix yet
Fix from $1,950 2010-08-26
Winamp HIGH 9.3
CVE-2009-3996EPSS 6%

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers t…

Fix: after 5.56
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-4356

Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via malformed (…

Fix: after 5.56
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-3995EPSS 7%

Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote a…

Fix: after 5.56
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-3997EPSS 6%

Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code via an O…

Fix: after 5.56
Fix from $1,950 2009-12-18
Winamp HIGH 9.3
CVE-2009-1831EPSS 36%

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted…

Fix: after 5.55
Fix from $1,950 2009-05-29
Winamp HIGH 9.3
CVE-2009-0186

Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted…

Fix: after 1.0.18
Fix from $1,950 2009-03-05
Winamp HIGH 10.0
CVE-2009-0263EPSS 17%

Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)…

Fix: after 5.541
Fix from $1,950 2009-01-23
Winamp HIGH 7.5
CVE-2008-3441

Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code …

Fix: 5.24+
Fix from $1,950 2008-08-01
Winamp HIGH 9.3
CVE-2007-2498EPSS 10%

libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of thes…

No fix yet
Fix from $1,950 2007-05-04
Winamp HIGH 7.1
CVE-2007-2180

Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file.

No fix yet
Fix from $1,950 2007-04-24
Winamp HIGH 9.3
CVE-2007-1921

LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT…

Mitigation only
Fix from $1,950 2007-04-10
Winamp HIGH 9.3
CVE-2007-1922

The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary cod…

Patch available
Fix from $1,950 2007-04-10
Winamp HIGH 9.3
CVE-2006-5567EPSS 14%

Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted …

Patch available
Fix from $1,950 2006-10-27
Shoutcast Server HIGH 7.8
CVE-2006-3534

Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote a…

Fix: after 1.9.5
Fix from $1,950 2006-07-12
Shoutcast Dsp MEDIUM 5.0
CVE-2006-3535

Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.7 allows remote attackers to read arbitrary files via unspecified vectors that…

Patch available
Fix from $1,600 2006-07-12
Winamp HIGH 9.3
CVE-2006-3228EPSS 12%

Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI…

Fix: after 5.23
Fix from $1,950 2006-06-26