Lucene search

K
nvd[email protected]NVD:CVE-2009-3996
HistoryDec 18, 2009 - 7:30 p.m.

CVE-2009-3996

2009-12-1819:30:00
CWE-119
web.nvd.nist.gov
6

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.192

Percentile

96.3%

Heap-based buffer overflow in IN_MOD.DLL (aka the Module Decoder Plug-in) in Winamp before 5.57, and libmikmod 3.1.12, might allow remote attackers to execute arbitrary code via an Ultratracker file.

Affected configurations

Nvd
Node
nullsoftwinampRange≀5.56
OR
nullsoftwinampMatch0.20a
OR
nullsoftwinampMatch0.92
OR
nullsoftwinampMatch1.006
OR
nullsoftwinampMatch1.90
OR
nullsoftwinampMatch2.0
OR
nullsoftwinampMatch2.4
OR
nullsoftwinampMatch2.5e
OR
nullsoftwinampMatch2.6
OR
nullsoftwinampMatch2.6x
OR
nullsoftwinampMatch2.7x
OR
nullsoftwinampMatch2.9
OR
nullsoftwinampMatch2.10
OR
nullsoftwinampMatch2.24
OR
nullsoftwinampMatch2.50
OR
nullsoftwinampMatch2.60
OR
nullsoftwinampMatch2.60full
OR
nullsoftwinampMatch2.60lite
OR
nullsoftwinampMatch2.61
OR
nullsoftwinampMatch2.61full
OR
nullsoftwinampMatch2.62
OR
nullsoftwinampMatch2.62standard
OR
nullsoftwinampMatch2.64
OR
nullsoftwinampMatch2.64standard
OR
nullsoftwinampMatch2.65
OR
nullsoftwinampMatch2.70
OR
nullsoftwinampMatch2.70full
OR
nullsoftwinampMatch2.71
OR
nullsoftwinampMatch2.72
OR
nullsoftwinampMatch2.73
OR
nullsoftwinampMatch2.73full
OR
nullsoftwinampMatch2.74
OR
nullsoftwinampMatch2.75
OR
nullsoftwinampMatch2.76
OR
nullsoftwinampMatch2.77
OR
nullsoftwinampMatch2.78
OR
nullsoftwinampMatch2.79
OR
nullsoftwinampMatch2.80
OR
nullsoftwinampMatch2.81
OR
nullsoftwinampMatch2.90
OR
nullsoftwinampMatch2.91
OR
nullsoftwinampMatch2.92
OR
nullsoftwinampMatch2.95
OR
nullsoftwinampMatch3.0
OR
nullsoftwinampMatch3.1
OR
nullsoftwinampMatch5.0
OR
nullsoftwinampMatch5.0.1
OR
nullsoftwinampMatch5.0.2
OR
nullsoftwinampMatch5.01
OR
nullsoftwinampMatch5.1
OR
nullsoftwinampMatch5.1-surround
OR
nullsoftwinampMatch5.02
OR
nullsoftwinampMatch5.2
OR
nullsoftwinampMatch5.3
OR
nullsoftwinampMatch5.03
OR
nullsoftwinampMatch5.03a
OR
nullsoftwinampMatch5.04
OR
nullsoftwinampMatch5.05
OR
nullsoftwinampMatch5.5
OR
nullsoftwinampMatch5.06
OR
nullsoftwinampMatch5.07
OR
nullsoftwinampMatch5.08
OR
nullsoftwinampMatch5.08c
OR
nullsoftwinampMatch5.08d
OR
nullsoftwinampMatch5.08e
OR
nullsoftwinampMatch5.08c
OR
nullsoftwinampMatch5.08d
OR
nullsoftwinampMatch5.08e
OR
nullsoftwinampMatch5.09
OR
nullsoftwinampMatch5.11
OR
nullsoftwinampMatch5.12
OR
nullsoftwinampMatch5.13
OR
nullsoftwinampMatch5.21
OR
nullsoftwinampMatch5.22
OR
nullsoftwinampMatch5.23
OR
nullsoftwinampMatch5.24
OR
nullsoftwinampMatch5.31
OR
nullsoftwinampMatch5.32
OR
nullsoftwinampMatch5.33
OR
nullsoftwinampMatch5.34
OR
nullsoftwinampMatch5.35
OR
nullsoftwinampMatch5.36
OR
nullsoftwinampMatch5.51
OR
nullsoftwinampMatch5.52
OR
nullsoftwinampMatch5.53
OR
nullsoftwinampMatch5.54
OR
nullsoftwinampMatch5.55
OR
nullsoftwinampMatch5.091
OR
nullsoftwinampMatch5.093
OR
nullsoftwinampMatch5.094
OR
nullsoftwinampMatch5.111
OR
nullsoftwinampMatch5.112
OR
nullsoftwinampMatch5.531
OR
nullsoftwinampMatch5.541
OR
nullsoftwinampMatch5.551
OR
nullsoftwinampMatch5.552
OR
raphael_assenatlibmikmodMatch3.1.12
VendorProductVersionCPE
nullsoftwinamp*cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:*
nullsoftwinamp0.20acpe:2.3:a:nullsoft:winamp:0.20a:*:*:*:*:*:*:*
nullsoftwinamp0.92cpe:2.3:a:nullsoft:winamp:0.92:*:*:*:*:*:*:*
nullsoftwinamp1.006cpe:2.3:a:nullsoft:winamp:1.006:*:*:*:*:*:*:*
nullsoftwinamp1.90cpe:2.3:a:nullsoft:winamp:1.90:*:*:*:*:*:*:*
nullsoftwinamp2.0cpe:2.3:a:nullsoft:winamp:2.0:*:*:*:*:*:*:*
nullsoftwinamp2.4cpe:2.3:a:nullsoft:winamp:2.4:*:*:*:*:*:*:*
nullsoftwinamp2.5ecpe:2.3:a:nullsoft:winamp:2.5e:*:*:*:*:*:*:*
nullsoftwinamp2.6cpe:2.3:a:nullsoft:winamp:2.6:*:*:*:*:*:*:*
nullsoftwinamp2.6xcpe:2.3:a:nullsoft:winamp:2.6x:*:*:*:*:*:*:*
Rows per page:
1-10 of 971

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.192

Percentile

96.3%