Lucene search

K
cveMitreCVE-2011-4857
HistoryDec 16, 2011 - 7:55 p.m.

CVE-2011-4857

2011-12-1619:55:01
CWE-119
mitre
web.nvd.nist.gov
19
cve-2011-4857
winamp
buffer overflow
in_mod.dll
security
vulnerability
nvd

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.05

Percentile

92.9%

Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message data in an Impulse Tracker (IT) file. NOTE: some of these details are obtained from third party information.

Affected configurations

Nvd
Node
nullsoftwinampRange≀5.622
OR
nullsoftwinampMatch0.20a
OR
nullsoftwinampMatch0.92
OR
nullsoftwinampMatch1.006
OR
nullsoftwinampMatch1.90
OR
nullsoftwinampMatch2.0
OR
nullsoftwinampMatch2.6
OR
nullsoftwinampMatch2.9
OR
nullsoftwinampMatch2.10
OR
nullsoftwinampMatch2.91
OR
nullsoftwinampMatch2.92
OR
nullsoftwinampMatch2.95
OR
nullsoftwinampMatch5.0
OR
nullsoftwinampMatch5.01
OR
nullsoftwinampMatch5.1-surround
OR
nullsoftwinampMatch5.02
OR
nullsoftwinampMatch5.2
OR
nullsoftwinampMatch5.3
OR
nullsoftwinampMatch5.03
OR
nullsoftwinampMatch5.04
OR
nullsoftwinampMatch5.05
OR
nullsoftwinampMatch5.5
OR
nullsoftwinampMatch5.6
OR
nullsoftwinampMatch5.06
OR
nullsoftwinampMatch5.07
OR
nullsoftwinampMatch5.08c
OR
nullsoftwinampMatch5.08d
OR
nullsoftwinampMatch5.08e
OR
nullsoftwinampMatch5.09
OR
nullsoftwinampMatch5.11
OR
nullsoftwinampMatch5.12
OR
nullsoftwinampMatch5.13
OR
nullsoftwinampMatch5.21
OR
nullsoftwinampMatch5.22
OR
nullsoftwinampMatch5.23
OR
nullsoftwinampMatch5.24
OR
nullsoftwinampMatch5.31
OR
nullsoftwinampMatch5.32
OR
nullsoftwinampMatch5.33
OR
nullsoftwinampMatch5.34
OR
nullsoftwinampMatch5.35
OR
nullsoftwinampMatch5.51
OR
nullsoftwinampMatch5.52
OR
nullsoftwinampMatch5.53
OR
nullsoftwinampMatch5.54
OR
nullsoftwinampMatch5.55
OR
nullsoftwinampMatch5.56
OR
nullsoftwinampMatch5.57
OR
nullsoftwinampMatch5.58
OR
nullsoftwinampMatch5.091
OR
nullsoftwinampMatch5.093
OR
nullsoftwinampMatch5.094
OR
nullsoftwinampMatch5.111
OR
nullsoftwinampMatch5.112
OR
nullsoftwinampMatch5.531
OR
nullsoftwinampMatch5.541
OR
nullsoftwinampMatch5.551
OR
nullsoftwinampMatch5.552
OR
nullsoftwinampMatch5.572
OR
nullsoftwinampMatch5.581
VendorProductVersionCPE
nullsoftwinamp*cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:*
nullsoftwinamp0.20acpe:2.3:a:nullsoft:winamp:0.20a:*:*:*:*:*:*:*
nullsoftwinamp0.92cpe:2.3:a:nullsoft:winamp:0.92:*:*:*:*:*:*:*
nullsoftwinamp1.006cpe:2.3:a:nullsoft:winamp:1.006:*:*:*:*:*:*:*
nullsoftwinamp1.90cpe:2.3:a:nullsoft:winamp:1.90:*:*:*:*:*:*:*
nullsoftwinamp2.0cpe:2.3:a:nullsoft:winamp:2.0:*:*:*:*:*:*:*
nullsoftwinamp2.6cpe:2.3:a:nullsoft:winamp:2.6:*:*:*:*:*:*:*
nullsoftwinamp2.9cpe:2.3:a:nullsoft:winamp:2.9:*:*:*:*:*:*:*
nullsoftwinamp2.10cpe:2.3:a:nullsoft:winamp:2.10:*:*:*:*:*:*:*
nullsoftwinamp2.91cpe:2.3:a:nullsoft:winamp:2.91:*:*:*:*:*:*:*
Rows per page:
1-10 of 601

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

High

EPSS

0.05

Percentile

92.9%

Related for CVE-2011-4857