Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 36% | 💥 Exploit | Nullsoft Winamp | 29/5/2009 | 16/6/2026 | The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow. | |
| Modificada | Alta (9.3) | 6.5% | — | Mega-nerd LibsndfileNullsoft Winamp | 26/5/2009 | 16/6/2026 | Heap-based buffer overflow in aiff_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an AIFF file with an invalid header value. | |
| Modificada | Alta (9.3) | 8.2% | — | Mega-nerd LibsndfileNullsoft Winamp | 26/5/2009 | 16/6/2026 | Heap-based buffer overflow in voc_read_header in libsndfile 1.0.15 through 1.0.19, as used in Winamp 5.552 and possibly other media programs, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a VOC file with an invalid header value. | |
| Modificada | Alta (9.3) | 3.6% | — | Nullsoft WinampMega-nerd Libsndfile | 5/3/2009 | 16/6/2026 | Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow. | |
| Modificada | Alta (10) | 17% | 💥 Exploit | Nullsoft Winamp | 23/1/2009 | 16/6/2026 | Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) header value in an AIFF file and (2) a large invalid value in an MP3 file. | |
| Modificada | Media (4.3) | 1.9% | — | Nullsoft Winamp | 10/8/2008 | 16/6/2026 | Cross-zone scripting vulnerability in the NowPlaying functionality in NullSoft Winamp before 5.541 allows remote attackers to conduct cross-site scripting (XSS) attacks via an MP3 file with JavaScript in id3 tags. | |
| Modificada | Alta (7.5) | 2.5% | — | Nullsoft Winamp | 1/8/2008 | 16/6/2026 | Nullsoft Winamp before 5.24 does not properly verify the authenticity of updates, which allows man-in-the-middle attackers to execute arbitrary code via a Trojan horse update, as demonstrated by evilgrade and DNS cache poisoning. | |
| Modificada | Alta (10) | 61% | 💥 Exploit | Nullsoft Winamp | 22/1/2008 | 16/6/2026 | Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Nullsoft Winamp | 17/12/2007 | 16/6/2026 | Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained in a certain .rar archive, a related issue to CVE-2007-2498. NOTE: for exploitation, the victim must select a certain menu option at the… | |
| Modificada | Alta (9.3) | 6.7% | — | LibflacNullsoft Winamp | 12/10/2007 | 16/6/2026 | Multiple integer overflows in Free Lossless Audio Codec (FLAC) libFLAC before 1.2.1, as used in Winamp before 5.5 and other products, allow user-assisted remote attackers to execute arbitrary code via a malformed FLAC file that triggers improper memory allocation, resulting in a heap-based buffer overflow. | |
| Modificada | Media (6.8) | 2.9% | — | Mirc Plug-in FOR Winamp | 18/8/2007 | 16/6/2026 | The mIRC Control Plug-in for Winamp allows user-assisted remote attackers to execute arbitrary code via the '|' (pipe) shell metacharacter in the name of the song in a .mp3 file. | |
| Modificada | Media (4.3) | 1.6% | — | Nullsoft Winamp | 17/8/2007 | 16/6/2026 | Winamp 5.35 allows remote attackers to cause a denial of service (program stack overflow and application crash) via an M3U file that recursively includes itself. | |
| Modificada | Alta (9.3) | 10% | 💥 Exploit | Nullsoft Winamp | 4/5/2007 | 16/6/2026 | libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.1) | 3.4% | 💥 Exploit | Nullsoft Winamp | 24/4/2007 | 16/6/2026 | Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a crafted WMV file. | |
| Modificada | Alta (9.3) | 4.8% | — | Nullsoft Winamp | 10/4/2007 | 16/6/2026 | The Impulse Tracker (IT) and ScreamTracker 3 (S3M) modules in IN_MOD.DLL in AOL Nullsoft Winamp 5.33 allows remote attackers to execute arbitrary code via a crafted (1) .IT or (2) .S3M file containing integer values that are used as memory offsets, which triggers memory corruption. | |
| Modificada | Alta (9.3) | 4.6% | — | Nullsoft Winamp | 10/4/2007 | 16/6/2026 | LIBSNDFILE.DLL, as used by AOL Nullsoft Winamp 5.33 and possibly other products, allows remote attackers to execute arbitrary code via a crafted .MAT file that contains a value that is used as an offset, which triggers memory corruption. | |
| Modificada | Media (4.3) | 2.8% | — | Mlipod Winamp Ipod Plugin | 14/12/2006 | 16/6/2026 | Buffer overflow in the readAA function in read_aa.cpp in Winamp iPod Plugin (ml_ipod) 2.00 p19 and earlier allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long tag in an audible.com audiobook (aa) file. | |
| Modificada | Alta (10) | 7.9% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Multiple buffer overflows in Winamp Web Interface (Wawi) 7.5.13 and earlier (1) allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via an (a) long username or a (b) crafted packet to the FindBasicAuth function in security.cpp, related to the /browse URI; and… | |
| Modificada | Baja (3.5) | 1.4% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | The CControl::Download function (/dl URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to download arbitrary file types under the root via a trailing "." (dot) in a filename in the file parameter, related to erroneous behavior of the IsWinampFile function. | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Directory traversal vulnerability in the Browse function (/browse URI) in Winamp Web Interface (Wawi) 7.5.13 and earlier allows remote authenticated users to list arbitrary directories via URL encoded backslashes ("%2F") in the path parameter. | |
| Modificada | Baja (3.5) | 1.3% | — | Flippet.org Winamp WEB Interface | 14/12/2006 | 16/6/2026 | Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target… | |
| Modificada | Alta (9.3) | 15% | 💥 Exploit | Nullsoft Winamp | 27/10/2006 | 16/6/2026 | Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags. | |
| Modificada | Alta (9.3) | 12% | 💥 Exploit | Nullsoft Winamp | 26/6/2006 | 16/6/2026 | Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file. | |
| Modificada | Alta (7.6) | 11% | 💥 Exploit | Nullsoft Winamp | 23/2/2006 | 16/6/2026 | Stack-based buffer overflow in Nullsoft Winamp 5.12 and 5.13 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted .m3u file that causes an incorrect strncpy function call when the player pauses or stops the file. | |
| Modificada | Alta (9.3) | 7.2% | — | Nullsoft Winamp | 15/2/2006 | 16/6/2026 | Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and… |