Back to Database
Status published
Critical
CVE-2007-2498
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers...
Vulnerability Description
libmp4v2.dll in Winamp 5.02 through 5.34 allows user-assisted remote attackers to execute arbitrary code via a certain .MP4 file. NOTE: some of these details are obtained from third party information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2498
Credits & Attribution
No credits recorded in the NVD database.
References
More from nullsoft
View All →CVE-2015-9268
Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit...
High
7.8
CVE-2015-9267
Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder...
Medium
5.5
CVE-2014-3442
Winamp 5.666 and earlier allows remote attackers to cause a...
Medium
4.3
CVE-2013-4694
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build...
High
7.5
CVE-2012-4045
Multiple heap-based buffer overflows in bmp.w5s in Winamp before 5.63...
High
7.5
Affected Vendor
nullsoft
View all reports →Affected Software
winamp
Vulnerable Versions:
5.2, 5.3, 5.21, 5.22, 5.23, 5.24, 5.31, 5.32, 5.33, 5.34
Timeline
Official Publish:
May 4th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.