CVE-2006-3228
high · 9.3Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.
9.3
CVSS
11.7%
EPSS (exploit prob.)
96th
EPSS percentile
2006-06-26
Published
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| nullsoft | winamp | <= 5.23 |
| nullsoft | winamp | 2.90 |
| nullsoft | winamp | 2.91 |
| nullsoft | winamp | 2.95 |
| nullsoft | winamp | 3.0 |
| nullsoft | winamp | 3.1 |
| nullsoft | winamp | 5.0 |
| nullsoft | winamp | 5.0.1 |
| nullsoft | winamp | 5.0.2 |
| nullsoft | winamp | 5.01 |
| nullsoft | winamp | 5.1 |
| nullsoft | winamp | 5.02 |
| nullsoft | winamp | 5.2 |
| nullsoft | winamp | 5.03 |
| nullsoft | winamp | 5.03a |
| nullsoft | winamp | 5.04 |
| nullsoft | winamp | 5.05 |
| nullsoft | winamp | 5.06 |
| nullsoft | winamp | 5.07 |
| nullsoft | winamp | 5.08c |
| nullsoft | winamp | 5.08d |
| nullsoft | winamp | 5.08e |
| nullsoft | winamp | 5.09 |
| nullsoft | winamp | 5.11 |
| nullsoft | winamp | 5.12 |
| nullsoft | winamp | 5.13 |
| nullsoft | winamp | 5.21 |
| nullsoft | winamp | 5.091 |
| nullsoft | winamp | 5.093 |
| nullsoft | winamp | 5.094 |
Check a specific version with /api/v1/cve/match.
References
- http://forums.winamp.com/showthread.php?threadid=248100
- http://secunia.com/advisories/20722
- http://www.attrition.org/pipermail/vim/2006-June/000892.html
- http://www.attrition.org/pipermail/vim/2006-June/000893.html
- http://www.winamp.com/about/article.php?aid=10694
- https://www.exploit-db.com/exploits/1935
- http://forums.winamp.com/showthread.php?threadid=248100
- http://secunia.com/advisories/20722
- http://www.attrition.org/pipermail/vim/2006-June/000892.html
- http://www.attrition.org/pipermail/vim/2006-June/000893.html
- http://www.winamp.com/about/article.php?aid=10694
- https://www.exploit-db.com/exploits/1935
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2006-3228