CVE-2011-4857: Nullsoft Winamp
High severity, CVSS 10.0. EPSS: 4.7% chance of exploitation in the next 30 days.
Heap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message data in an Impulse Tracker (IT) file. NOTE: some of these details are obtained from third party information.
Affected products
- Nullsoft Winamp: up to and including 5.622; version 0.20a only; version 0.92 only; version 1.006 only; version 1.90 only; version 2.0 only; …
Published 2011-12-16. Last modified 2026-06-16.