Winamp maintains a legacy media player and related tools whose vulnerability footprint, while narrow in product scope, has attracted public exploit tooling. The recurring exposure centers on memory-safety issues including improper buffer-boundary restrictions and invalid pointer dereferences, characteristic of native-code audio and format-parsing components. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Winamp over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0065HIGH Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox | Jan 22, 2008 | 10.0 | 77 | NO | YES |
CVE-2013-4695HIGH Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution | Dec 27, 2019 | 7.8 | 31 | NO | YES |
CVE-2007-6403MEDIUM Stack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 file, with crafted tags, contained | Dec 17, 2007 | 6.8 | 27 | NO | YES |
CVE-2017-10728HIGH Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Error Code (0xe06d7363) starting at w | Jul 5, 2017 | 7.8 | 21 | NO | NO |
CVE-2017-10727HIGH Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls B | Jul 5, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-10726HIGH Winamp 5.666 Build 3516(x86) might allow attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address may be use | Jul 5, 2017 | 7.8 | 20 | NO | NO |
CVE-2017-10725HIGH Winamp 5.666 Build 3516(x86) allows attackers to execute arbitrary code or cause a denial of service via a crafted .flv file, related to "Data from Faulting Address controls Code F | Jul 5, 2017 | 7.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Winamp.
Media articles that mention a CVE ID that affects a product developed by Winamp — matched by CVE ID, not by vendor name.