← All CVEs

CVE-2009-1831

high · 9.3

The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.

9.3
CVSS
36.3%
EPSS (exploit prob.)
98th
EPSS percentile
2009-05-29
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-189

Affected products

VendorProductAffected versions
nullsoftwinamp<= 5.55
nullsoftwinamp2.0
nullsoftwinamp2.4
nullsoftwinamp2.5e
nullsoftwinamp2.6x
nullsoftwinamp2.7x
nullsoftwinamp2.10
nullsoftwinamp2.24
nullsoftwinamp2.50
nullsoftwinamp2.60
nullsoftwinamp2.60
nullsoftwinamp2.60
nullsoftwinamp2.61
nullsoftwinamp2.61
nullsoftwinamp2.62
nullsoftwinamp2.62
nullsoftwinamp2.64
nullsoftwinamp2.64
nullsoftwinamp2.65
nullsoftwinamp2.70
nullsoftwinamp2.70
nullsoftwinamp2.71
nullsoftwinamp2.72
nullsoftwinamp2.73
nullsoftwinamp2.73
nullsoftwinamp2.74
nullsoftwinamp2.75
nullsoftwinamp2.76
nullsoftwinamp2.77
nullsoftwinamp2.78
nullsoftwinamp2.79
nullsoftwinamp2.80
nullsoftwinamp2.81
nullsoftwinamp2.90
nullsoftwinamp2.91
nullsoftwinamp2.95
nullsoftwinamp3.0
nullsoftwinamp3.1
nullsoftwinamp5.0
nullsoftwinamp5.0.1

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-1831