Lucene search

K
cveFlexeraCVE-2010-2586
HistoryDec 02, 2010 - 4:22 p.m.

CVE-2010-2586

2010-12-0216:22:20
CWE-189
flexera
web.nvd.nist.gov
34
cve-2010-2586
integer overflows
in_nsv.dll
in_nsv plugin
winamp
remote code execution
heap-based buffer overflow
nvd
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.109

Percentile

95.1%

Multiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Table of Contents (TOC) in a (1) NSV stream or (2) NSV file that triggers a heap-based buffer overflow.

Affected configurations

Nvd
Node
nullsoftwinampRange5.581
OR
nullsoftwinampMatch0.20a
OR
nullsoftwinampMatch0.92
OR
nullsoftwinampMatch1.006
OR
nullsoftwinampMatch1.90
OR
nullsoftwinampMatch2.0
OR
nullsoftwinampMatch2.6
OR
nullsoftwinampMatch2.9
OR
nullsoftwinampMatch2.10
OR
nullsoftwinampMatch2.91
OR
nullsoftwinampMatch2.92
OR
nullsoftwinampMatch2.95
OR
nullsoftwinampMatch5.0
OR
nullsoftwinampMatch5.01
OR
nullsoftwinampMatch5.1-surround
OR
nullsoftwinampMatch5.02
OR
nullsoftwinampMatch5.2
OR
nullsoftwinampMatch5.3
OR
nullsoftwinampMatch5.03
OR
nullsoftwinampMatch5.04
OR
nullsoftwinampMatch5.05
OR
nullsoftwinampMatch5.5
OR
nullsoftwinampMatch5.06
OR
nullsoftwinampMatch5.07
OR
nullsoftwinampMatch5.08c
OR
nullsoftwinampMatch5.08d
OR
nullsoftwinampMatch5.08e
OR
nullsoftwinampMatch5.09
OR
nullsoftwinampMatch5.11
OR
nullsoftwinampMatch5.12
OR
nullsoftwinampMatch5.13
OR
nullsoftwinampMatch5.21
OR
nullsoftwinampMatch5.22
OR
nullsoftwinampMatch5.23
OR
nullsoftwinampMatch5.24
OR
nullsoftwinampMatch5.31
OR
nullsoftwinampMatch5.32
OR
nullsoftwinampMatch5.33
OR
nullsoftwinampMatch5.34
OR
nullsoftwinampMatch5.35
OR
nullsoftwinampMatch5.51
OR
nullsoftwinampMatch5.52
OR
nullsoftwinampMatch5.53
OR
nullsoftwinampMatch5.54
OR
nullsoftwinampMatch5.55
OR
nullsoftwinampMatch5.56
OR
nullsoftwinampMatch5.58
OR
nullsoftwinampMatch5.091
OR
nullsoftwinampMatch5.093
OR
nullsoftwinampMatch5.094
OR
nullsoftwinampMatch5.111
OR
nullsoftwinampMatch5.112
OR
nullsoftwinampMatch5.531
OR
nullsoftwinampMatch5.541
OR
nullsoftwinampMatch5.551
OR
nullsoftwinampMatch5.552
OR
nullsoftwinampMatch5.572
VendorProductVersionCPE
nullsoftwinamp*cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:*
nullsoftwinamp0.20acpe:2.3:a:nullsoft:winamp:0.20a:*:*:*:*:*:*:*
nullsoftwinamp0.92cpe:2.3:a:nullsoft:winamp:0.92:*:*:*:*:*:*:*
nullsoftwinamp1.006cpe:2.3:a:nullsoft:winamp:1.006:*:*:*:*:*:*:*
nullsoftwinamp1.90cpe:2.3:a:nullsoft:winamp:1.90:*:*:*:*:*:*:*
nullsoftwinamp2.0cpe:2.3:a:nullsoft:winamp:2.0:*:*:*:*:*:*:*
nullsoftwinamp2.6cpe:2.3:a:nullsoft:winamp:2.6:*:*:*:*:*:*:*
nullsoftwinamp2.9cpe:2.3:a:nullsoft:winamp:2.9:*:*:*:*:*:*:*
nullsoftwinamp2.10cpe:2.3:a:nullsoft:winamp:2.10:*:*:*:*:*:*:*
nullsoftwinamp2.91cpe:2.3:a:nullsoft:winamp:2.91:*:*:*:*:*:*:*
Rows per page:
1-10 of 571

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

High

EPSS

0.109

Percentile

95.1%