VulnerabilityModified
CVE-2004-1396
Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.
LOW 2.6EPSS 3.09%
Does this matter?
Lower severity and a low EPSS score (3.09%). Track it; it rarely justifies an emergency change on its own.
Description
Winamp 5.07 and possibly other versions, allows remote attackers to cause a denial of service (application crash or CPU consumption) via (1) an mp4 or m4a playlist file that contains invalid tag data or (2) an invalid .nsv or .nsa file.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:N/A:P
- EPSS
- 3.09% probability · 87th percentile
- CISA KEV
- Not listed
- Affected
- nullsoft/winamp
- Source
- cve@mitre.org
References
- http://forums.winamp.com/showthread.php?s=&threadid=202007Exploit
- http://marc.info/?l=bugtraq&m=110297310503541&w=2
- http://marc.info/?l=full-disclosure&m=110303988101973&w=2
- http://securitytracker.com/alerts/2004/Dec/1012525.html
- http://www.kb.cert.org/vuls/id/372968US Government Resource
- http://www.securityfocus.com/bid/11909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18466
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18467
- http://forums.winamp.com/showthread.php?s=&threadid=202007Exploit
- http://marc.info/?l=bugtraq&m=110297310503541&w=2
- http://marc.info/?l=full-disclosure&m=110303988101973&w=2
- http://securitytracker.com/alerts/2004/Dec/1012525.html
- http://www.kb.cert.org/vuls/id/372968US Government Resource
- http://www.securityfocus.com/bid/11909
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18466
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18467
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.