CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8097 | CVE-2003-1273 | Candidate | Winamp 3.0 allows remote attackers to cause a denial of service (crash) via a .b4s file with a playlist name that contains some non-English characters, e.g. Cyrillic characters. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8098 | CVE-2003-1274 | Candidate | Winamp 3.0 allows remote attackers to cause a denial of service (crash) via .b4s file with a file: argument to the Playstring parameter that contains MS-DOS device names such as aux. | Assigned (20051116) | None (candidate not yet proposed) | View | |
6794 | CVE-2002-2412 | Candidate | Winamp 2.80 stores authentication credentials in plaintext in the (1) [HTTP-AUTH] and (2) [winamp] sections in winamp.ini, which allows local users to gain access to other accounts. | Assigned (20071101) | None (candidate not yet proposed) | View | |
4676 | CVE-2002-0284 | Candidate | Winamp 2.78 and 2.77, when opening a wma file that requires a license, sends the full path of the Temporary Internet Files directory to the web page that is processing the license, which could allow malicious web servers to obtain the pathname. | Proposed (20020502) | MODIFY(1) Frech | NOOP(5) Armstrong, Cole, Cox, Foat, Wall | CHANGE> [Frech changed vote from REVIEWING to MODIFY] | Frech> XF:winamp-wma-pathname-disclosure(10030) | View |
6774 | CVE-2002-2392 | Candidate | Winamp 2.65 through 3.0 stores skin files in a predictable file location, which allows remote attackers to execute arbitrary code via a URL reference to (1) wsz and (2) wal files that contain embedded code. | Assigned (20071031) | None (candidate not yet proposed) | View |
Page 193 of 20943, showing 5 records out of 104715 total, starting on record 961, ending on 965