Back to Database
Status published
Critical
CVE-2006-3228
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23,...
Vulnerability Description
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3228
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.attrition.org/pipermail/vim/2006-June/000892.html
- http://secunia.com/advisories/20722
- https://www.exploit-db.com/exploits/1935
- http://www.winamp.com/about/article.php?aid=10694
- http://forums.winamp.com/showthread.php?threadid=248100
- http://www.attrition.org/pipermail/vim/2006-June/000893.html
More from nullsoft
View All →CVE-2015-9268
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit...
High
7.8
CVE-2015-9267
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder...
Medium
5.5
CVE-2014-3442
Winamp 5.666 and earlier allows remote attackers to cause a...
Medium
4.3
CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build...
High
7.5
CVE-2012-4045
Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63...
High
7.5
Affected Vendor
nullsoft
View all reports →Affected Software
winamp
Vulnerable Versions:
0, 2.90, 2.91, 2.95, 3.0, 3.1, 5.0, 5.0.1, 5.0.2, 5.01, 5.1, 5.02, 5.2, 5.03, 5.03a, 5.04, 5.05, 5.06, 5.07, 5.08c, 5.08d, 5.08e, 5.09, 5.11, 5.12, 5.13, 5.21, 5.091, 5.093, 5.094
Timeline
Official Publish:
June 26th, 2006
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.