CVE-2012-3889: Nullsoft Winamp

Medium severity, CVSS 6.8. EPSS: 2% chance of exploitation in the next 30 days.

The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a .IT file.

Affected products

  • Nullsoft Winamp: up to and including 5.623; version 0.20a only; version 0.92 only; version 1.006 only; version 1.90 only; version 2.0 only; …

Published 2012-07-11. Last modified 2026-06-16.