CVE-2009-1831
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 36%
from disclosure to weapon1202 days
Published on NVDMay 29
1st PoC+1202d
metasploitMay 20
exploitation probability
36%top 2% of all CVEs
observed exploitation
nono source reports it
5 public exploit(s)
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an incorrect sign extension, an integer overflow, and a stack-based buffer overflow.
Affected products
n/a · n/apublic PoCs found — 5
cve_referencewww.exploit-db.com/exploits/8767unverifiedexploitdbwww.exploit-db.com/exploits/21256unverifiedcve_referencewww.exploit-db.com/exploits/8772unverifiedcve_referencewww.exploit-db.com/exploits/8770unverifiedcve_referencewww.exploit-db.com/exploits/8783unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://exchange.xforce.ibmcloud.com/vulnerabilities/50664https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15683https://www.exploit-db.com/exploits/8767https://www.exploit-db.com/exploits/8770https://www.exploit-db.com/exploits/8772https://www.exploit-db.com/exploits/8783http://vrt-sourcefire.blogspot.com/2009/05/winamp-maki-parsing-vulnerability.htmlhttp://www.securityfocus.com/bid/35052