← Vulnerability feed

Vulnerability record · CVE-2006-0476 · published 31 January 2006

CVE-2006-0476: Winamp 5.12 playlist file name buffer overflow

Nullsoft · Winamp

Nullsoft Winamp 5.12 contains a buffer overflow triggered by a long file name in the File1 field of a playlist (.pls) file. Opening a crafted playlist can corrupt memory and allow code execution in the context of the user running Winamp.

7.6 CVSS 2.0 High EPSS 75% · top 0.5%
7.6CVSS 2.0 base score
75%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).

AV:N/AC:H/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityPublic exploit code and a very high EPSS score make exploitation likely, though the high attack complexity and required user interaction temper the risk.

What it is

Nullsoft Winamp 5.12 contains a buffer overflow triggered by a long file name in the File1 field of a playlist (.pls) file. Opening a crafted playlist can corrupt memory and allow code execution in the context of the user running Winamp.

Impact

An attacker can execute arbitrary code with the privileges of the Winamp user, leading to full compromise of the host under that account. The CVSS 2.0 vector rates confidentiality, integrity, and availability impact as complete.

Attack surface

The flaw is reached remotely by delivering a malicious .pls file that the victim opens in Winamp; no authentication is required, but user interaction (opening the playlist) is needed. The CVSS 2.0 vector is AV:N/AC:H/Au:N, indicating network delivery with high attack complexity.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.74993, 99.482nd percentile) and a public Exploit-DB entry (3422) exists, indicating exploit code is publicly available. No ransomware usage is documented.

What to do

  • Upgrade Winamp to a version later than 5.12 that addresses the playlist parsing overflow.
  • Apply the vendor patch referenced in the Secunia advisory (SA18649) if upgrading is not immediately possible.
  • Block or strip .pls attachments and downloads at email and web gateways where feasible.
  • Train users not to open playlist files from untrusted sources.
  • Consider application allowlisting or endpoint controls to limit execution of untrusted media files.

Detection

  • Monitor for Winamp processes spawning unexpected child processes or making unusual network connections after opening a .pls file.
  • Inspect .pls files for abnormally long File1 values or oversized file name fields.
  • Use endpoint detection to flag crashes or memory corruption events in winamp.exe.
  • Review file transfer and email logs for .pls files arriving from external or untrusted senders.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/18649 PatchVendor Advisory
http://securityreason.com/securityalert/386
http://securityreason.com/securityalert/398
http://securitytracker.com/id?1015552
http://www.heise.de/newsticker/meldung/68981
http://www.kb.cert.org/vuls/id/604745 US Government Resource
http://www.osvdb.org/22789
http://www.securityfocus.com/archive/1/423436/100/0/threaded
http://www.securityfocus.com/archive/1/423548/100/0/threaded
http://www.securityfocus.com/bid/16410
http://www.us-cert.gov/cas/techalerts/TA06-032A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0361
http://www.winamp.com/player/version_history.php
https://exchange.xforce.ibmcloud.com/vulnerabilities/24361
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1402
https://www.exploit-db.com/exploits/3422
http://secunia.com/advisories/18649 PatchVendor Advisory
http://securityreason.com/securityalert/386
http://securityreason.com/securityalert/398
http://securitytracker.com/id?1015552
http://www.heise.de/newsticker/meldung/68981
http://www.kb.cert.org/vuls/id/604745 US Government Resource
http://www.osvdb.org/22789
http://www.securityfocus.com/archive/1/423436/100/0/threaded
http://www.securityfocus.com/archive/1/423548/100/0/threaded
http://www.securityfocus.com/bid/16410
http://www.us-cert.gov/cas/techalerts/TA06-032A.html US Government Resource
http://www.vupen.com/english/advisories/2006/0361
http://www.winamp.com/player/version_history.php
https://exchange.xforce.ibmcloud.com/vulnerabilities/24361
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1402
https://www.exploit-db.com/exploits/3422

Track CVE-2006-0476 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2011-4857Nullsoft winamp memory buffer overflow vulnerabilityHeap-based buffer overflow in the in_mod.dll plugin in Winamp before 5.623 allows remote attackers to execute arbitrary code via crafted song message…EPSS 4.7%10.0CVE-2009-0263Nullsoft winamp memory buffer overflow vulnerabilityMultiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1)…EPSS 17%10.0CVE-2004-1119Nullsoft winamp vulnerabilityStack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary c…EPSS 17%9.3CVE-2011-3834Nullsoft winamp vulnerabilityMultiple integer overflows in the in_avi.dll plugin in Winamp before 5.623 allow remote attackers to execute arbitrary code via an AVI file with a cr…EPSS 5.1%9.3CVE-2010-4372Nullsoft winamp vulnerabilityInteger overflow in the in_nsv plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to improper allo…EPSS 2.8%9.3CVE-2010-4370Nullsoft winamp vulnerabilityMultiple integer overflows in the in_midi plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted MIDI file that t…EPSS 5.1%9.3CVE-2010-4371Nullsoft winamp memory buffer overflow vulnerabilityBuffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment bo…EPSS 6.1%9.3CVE-2010-2586Nullsoft winamp vulnerabilityMultiple integer overflows in in_nsv.dll in the in_nsv plugin in Winamp before 5.6 allow remote attackers to execute arbitrary code via a crafted Tab…EPSS 5.5%

Source: NIST National Vulnerability Database (record CVE-2006-0476), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.