← All CVEs

CVE-2013-4694

high · 7.5

Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.

7.5
CVSS
17.2%
EPSS (exploit prob.)
97th
EPSS percentile
2014-04-16
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Weaknesses

CWE-119

Affected products

VendorProductAffected versions
nullsoftwinamp<= 5.63
nullsoftwinamp0.20a
nullsoftwinamp0.92
nullsoftwinamp1.006
nullsoftwinamp1.90
nullsoftwinamp2.0
nullsoftwinamp2.6
nullsoftwinamp2.9
nullsoftwinamp2.10
nullsoftwinamp2.91
nullsoftwinamp2.92
nullsoftwinamp2.95
nullsoftwinamp5.0
nullsoftwinamp5.01
nullsoftwinamp5.1
nullsoftwinamp5.02
nullsoftwinamp5.2
nullsoftwinamp5.3
nullsoftwinamp5.03
nullsoftwinamp5.04
nullsoftwinamp5.05
nullsoftwinamp5.5
nullsoftwinamp5.06
nullsoftwinamp5.07
nullsoftwinamp5.08c
nullsoftwinamp5.08d
nullsoftwinamp5.08e
nullsoftwinamp5.09
nullsoftwinamp5.11
nullsoftwinamp5.12
nullsoftwinamp5.13
nullsoftwinamp5.21
nullsoftwinamp5.22
nullsoftwinamp5.23
nullsoftwinamp5.24
nullsoftwinamp5.31
nullsoftwinamp5.32
nullsoftwinamp5.33
nullsoftwinamp5.34
nullsoftwinamp5.35

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2013-4694