CVE-2012-3890

UnknownEPSS 2.02%

Last modified

CVE-2012-3890 is a vulnerability of currently unknown severity. The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a .IT file.. EPSS estimates a 2.02% chance of exploitation in the next 30 days.

Description

The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a .IT file.

Metrics

EPSS Probability
2.02%

78.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
NullsoftWinamp<= 5.623—
NullsoftWinamp0.20a—
NullsoftWinamp0.92—
NullsoftWinamp1.006—
NullsoftWinamp1.90—
NullsoftWinamp2.0—
NullsoftWinamp2.6—
NullsoftWinamp2.9—
NullsoftWinamp2.10—
NullsoftWinamp2.91—
NullsoftWinamp2.92—
NullsoftWinamp2.95—
NullsoftWinamp5.0—
NullsoftWinamp5.01—
NullsoftWinamp5.1—
NullsoftWinamp5.02—
NullsoftWinamp5.2—
NullsoftWinamp5.3—
NullsoftWinamp5.03—
NullsoftWinamp5.04—
NullsoftWinamp5.05—
NullsoftWinamp5.5—
NullsoftWinamp5.06—
NullsoftWinamp5.07—
NullsoftWinamp5.08c—
NullsoftWinamp5.08d—
NullsoftWinamp5.08e—
NullsoftWinamp5.09—
NullsoftWinamp5.11—
NullsoftWinamp5.12—
NullsoftWinamp5.13—
NullsoftWinamp5.21—
NullsoftWinamp5.22—
NullsoftWinamp5.23—
NullsoftWinamp5.24—
NullsoftWinamp5.31—
NullsoftWinamp5.32—
NullsoftWinamp5.33—
NullsoftWinamp5.34—
NullsoftWinamp5.35—
NullsoftWinamp5.36—
NullsoftWinamp5.51—
NullsoftWinamp5.52—
NullsoftWinamp5.53—
NullsoftWinamp5.54—
NullsoftWinamp5.55—
NullsoftWinamp5.56—
NullsoftWinamp5.57—
NullsoftWinamp5.59Beta
NullsoftWinamp5.61—

Showing 50 of 59 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-3890?
The in_mod plugin in Winamp before 5.63 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a .IT file.
How severe is CVE-2012-3890?
Severity scoring for CVE-2012-3890 is pending analysis. The EPSS model estimates a 2.02% probability of exploitation in the next 30 days.
How do I fix CVE-2012-3890?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2012

Are you affected by CVE-2012-3890?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST