CVE-2006-5567

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/10/2006
Last modified:
09/04/2025

Description

Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nullsoft:winamp:5.3:*:*:*:*:*:*:*
cpe:2.3:a:nullsoft:winamp:5.24:*:*:*:*:*:*:*