CVE-2010-4371 describes a critical buffer overflow vulnerability in the in_mod plugin of Winamp versions prior to 5.6. This flaw allows remote attackers to achieve significant impact through specially crafted input related to the comment box. With a CVSS score of 9.3, this vulnerability is highly severe, indicating it can be exploited remotely with medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. The EPSS and FAUCET scores also highlight its high potential for exploitation. While not listed on the KEV catalog or Hot List, and lacking active Metasploit or Nuclei modules, several ExploitDB entries confirm the existence of exploit code for various buffer overflow scenarios within the in_mod plugin. Despite this, there is minimal community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.581CPE matchmatch criteria | cpe:2.3:a:nullsoft:winamp:*:*:*:*:*:*:*:* | ||
0.20aCPE matchmatch criteria | cpe:2.3:a:nullsoft:winamp:0.20a:*:*:*:*:*:*:* | ||
0.92CPE matchmatch criteria | cpe:2.3:a:nullsoft:winamp:0.92:*:*:*:*:*:*:* | ||
1.006CPE matchmatch criteria | cpe:2.3:a:nullsoft:winamp:1.006:*:*:*:*:*:*:* | ||
1.90CPE matchmatch criteria | cpe:2.3:a:nullsoft:winamp:1.90:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.