Nullsoft records
77 published records for vendor nullsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 3 · 3.9%
- Pre-auth RCE
- 46
- With a fix record
- 13%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer15
- CWE-189 Numeric Errors9
- CWE-20 Improper Input Validation2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-427 Uncontrolled Search Path Element1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
77 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
52Plan | CVE-2006-0476Weaponized | Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (Fnullsoft · winamp | High7.6 | — | 75.0% | Jan 31, 2006 |
51Plan | CVE-2004-1373Weaponized | Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrarnullsoft · shoutcast server | High7.5 | — | 70.1% | Dec 23, 2004 |
48Plan | CVE-2009-1831Weaponized | The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via nullsoft · winamp · CWE-189 | Critical9.3 | — | 36.3% | May 29, 2009 |
45Plan | CVE-2004-1119Proof of concept | Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arnullsoft · winamp | Critical10.0 | — | 17.3% | Jan 10, 2005 |
45Plan | CVE-2009-0263Proof of concept | Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary codnullsoft · winamp · CWE-119 | Critical10.0 | — | 16.7% | Jan 23, 2009 |
41Plan | CVE-2006-5567Proof of concept | Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via anullsoft · winamp | Critical9.3 | — | 14.5% | Oct 27, 2006 |
41Plan | CVE-2005-2310Proof of concept | Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an Mnullsoft · winamp · CWE-119 | Critical9.3 | — | 13.1% | Jul 19, 2005 |
41Plan | CVE-2006-3228Proof of concept | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .nullsoft · winamp | Critical9.3 | — | 11.7% | Jun 26, 2006 |
41Plan | CVE-2011-4857No exploit | Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted sonnullsoft · winamp · CWE-119 | Critical10.0 | — | 4.7% | Dec 16, 2011 |
40Plan | CVE-2007-2498Proof of concept | libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file.nullsoft · winamp | Critical9.3 | — | 10.2% | May 3, 2007 |
40Plan | CVE-2009-0833Proof of concept | Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via myplugins · gen msn · CWE-119 | Critical9.3 | — | 9.3% | Mar 5, 2009 |
39Monitor | CVE-2009-1788No exploit | Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programsmega-nerd · libsndfile · CWE-119 | Critical9.3 | — | 8.2% | May 26, 2009 |
39Monitor | CVE-2010-3137Proof of concept | Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackersnullsoft · winamp | Critical9.3 | — | 7.8% | Aug 26, 2010 |
39Monitor | CVE-2006-0708No exploit | Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containinnullsoft · winamp | Critical9.3 | — | 7.2% | Feb 15, 2006 |
39Monitor | CVE-2007-4619No exploit | Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow flac · libflac · CWE-189 | Critical9.3 | — | 6.7% | Oct 12, 2007 |
39Monitor | CVE-2009-3995No exploit | Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allownullsoft · winamp · CWE-119 | Critical9.3 | — | 6.7% | Dec 18, 2009 |
39Monitor | CVE-2009-1791No exploit | Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programmega-nerd · libsndfile · CWE-119 | Critical9.3 | — | 6.5% | May 26, 2009 |
39Monitor | CVE-2009-3996No exploit | Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote atnullsoft · winamp · CWE-119 | Critical9.3 | — | 6.5% | Dec 18, 2009 |
39Monitor | CVE-2010-4371Proof of concept | Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the cnullsoft · winamp · CWE-119 | Critical9.3 | — | 6.1% | Dec 2, 2010 |
39Monitor | CVE-2009-3997No exploit | Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary codenullsoft · winamp · CWE-189 | Critical9.3 | — | 5.7% | Dec 18, 2009 |
39Monitor | CVE-2010-2586No exploit | Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crnullsoft · winamp · CWE-189 | Critical9.3 | — | 5.5% | Dec 2, 2010 |
39Monitor | CVE-2010-1523No exploit | Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to exnullsoft · winamp · CWE-119 | Critical9.3 | — | 5.3% | Nov 5, 2010 |
39Monitor | CVE-2010-4370No exploit | Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI finullsoft · winamp · CWE-189 | Critical9.3 | — | 5.1% | Dec 2, 2010 |
39Monitor | CVE-2011-3834No exploit | Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file nullsoft · winamp · CWE-189 | Critical9.3 | — | 5.1% | Dec 16, 2011 |
38Monitor | CVE-2009-4356No exploit | Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via manullsoft · winamp · CWE-189 | Critical9.3 | — | 5.0% | Dec 18, 2009 |
- CVE-2006-047652Plan
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (F
HighCVSS 7.6WeaponizedEPSS 75%nullsoft · winampJan 31, 2006
- CVE-2004-137351Plan
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrar
HighCVSS 7.5WeaponizedEPSS 70%nullsoft · shoutcast serverDec 23, 2004
- CVE-2009-183148Plan
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via
CriticalCVSS 9.3WeaponizedEPSS 36%nullsoft · winampMay 29, 2009
- CVE-2004-111945Plan
Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute ar
CriticalCVSS 10.0Proof of conceptEPSS 17%nullsoft · winampJan 10, 2005
- CVE-2009-026345Plan
Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary cod
CriticalCVSS 10.0Proof of conceptEPSS 17%nullsoft · winampJan 23, 2009
- CVE-2006-556741Plan
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a
CriticalCVSS 9.3Proof of conceptEPSS 15%nullsoft · winampOct 27, 2006
- CVE-2005-231041Plan
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an M
CriticalCVSS 9.3Proof of conceptEPSS 13%nullsoft · winampJul 19, 2005
- CVE-2006-322841Plan
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .
CriticalCVSS 9.3Proof of conceptEPSS 12%nullsoft · winampJun 26, 2006
- CVE-2011-485741Plan
Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted son
CriticalCVSS 10.0No exploitEPSS 5%nullsoft · winampDec 16, 2011
- CVE-2007-249840Plan
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file.
CriticalCVSS 9.3Proof of conceptEPSS 10%nullsoft · winampMay 3, 2007
- CVE-2009-083340Plan
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute arbitrary code via
CriticalCVSS 9.3Proof of conceptEPSS 9%myplugins · gen msnMar 5, 2009
- CVE-2009-178839Monitor
Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs
CriticalCVSS 9.3No exploitEPSS 8%mega-nerd · libsndfileMay 26, 2009
- CVE-2010-313739Monitor
Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers
CriticalCVSS 9.3Proof of conceptEPSS 8%nullsoft · winampAug 26, 2010
- CVE-2006-070839Monitor
Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containin
CriticalCVSS 9.3No exploitEPSS 7%nullsoft · winampFeb 15, 2006
- CVE-2007-461939Monitor
Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow
CriticalCVSS 9.3No exploitEPSS 7%flac · libflacOct 12, 2007
- CVE-2009-399539Monitor
Multiple heap-based buffer overflows in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow
CriticalCVSS 9.3No exploitEPSS 7%nullsoft · winampDec 18, 2009
- CVE-2009-179139Monitor
Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media program
CriticalCVSS 9.3No exploitEPSS 7%mega-nerd · libsndfileMay 26, 2009
- CVE-2009-399639Monitor
Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote at
CriticalCVSS 9.3No exploitEPSS 6%nullsoft · winampDec 18, 2009
- CVE-2010-437139Monitor
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the c
CriticalCVSS 9.3Proof of conceptEPSS 6%nullsoft · winampDec 2, 2010
- CVE-2009-399739Monitor
Integer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57 might allow remote attackers to execute arbitrary code
CriticalCVSS 9.3No exploitEPSS 6%nullsoft · winampDec 18, 2009
- CVE-2010-258639Monitor
Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a cr
CriticalCVSS 9.3No exploitEPSS 6%nullsoft · winampDec 2, 2010
- CVE-2010-152339Monitor
Multiple heap-based buffer overflows in vp6.w5s (aka the VP6 codec) in Winamp before 5.59 Beta build 3033 might allow remote attackers to ex
CriticalCVSS 9.3No exploitEPSS 5%nullsoft · winampNov 5, 2010
- CVE-2010-437039Monitor
Multiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI fi
CriticalCVSS 9.3No exploitEPSS 5%nullsoft · winampDec 2, 2010
- CVE-2011-383439Monitor
Multiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file
CriticalCVSS 9.3No exploitEPSS 5%nullsoft · winampDec 16, 2011
- CVE-2009-435638Monitor
Multiple integer overflows in the jpeg.w5s and png.w5s filters in Winamp before 5.57 allow remote attackers to execute arbitrary code via ma
CriticalCVSS 9.3No exploitEPSS 5%nullsoft · winampDec 18, 2009