CVE-2013-4694: Nullsoft Winamp
High severity, CVSS 7.5. EPSS: 17.2% chance of exploitation in the next 30 days.
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
Affected products
- Nullsoft Winamp: up to and including 5.63; version 0.20a only; version 0.92 only; version 1.006 only; version 1.90 only; version 2.0 only; …
Published 2014-04-16. Last modified 2026-06-16.