← Vulnerability feed

Vulnerability record · CVE-2008-0065 · published 22 January 2008

CVE-2008-0065: Winamp in_mp3.dll stack buffer overflow via Ultravox metadata tags

Winamp · Nullsoft Winamp

Winamp 5.21, 5.5, and 5.51 contain multiple stack-based buffer overflows in in_mp3.dll triggered by long artist or name tags in Ultravox streaming metadata, related to stream title construction. A remote attacker can crash the player or execute arbitrary code in the context of the user running Winamp.

10.0 CVSS 2.0 High EPSS 61% · top 0.9% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in in_mp3.dll in Winamp 5.21, 5.5, and 5.51 allow remote attackers to execute arbitrary code via a long (1) artist or (2) name tag in Ultravox streaming metadata, related to construction of stream titles.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 2.0 base score of 10 with network vector, no authentication, and full confidentiality, integrity, and availability impact, tempered by the age of the product and lack of confirmed in-the-wild exploitation.

What it is

Winamp 5.21, 5.5, and 5.51 contain multiple stack-based buffer overflows in in_mp3.dll triggered by long artist or name tags in Ultravox streaming metadata, related to stream title construction. A remote attacker can crash the player or execute arbitrary code in the context of the user running Winamp.

Impact

Successful exploitation allows remote code execution with the privileges of the Winamp process, giving an attacker full control of the affected host. At minimum, a crafted stream can crash the player.

Attack surface

Reached over the network via a malicious or compromised Ultravox stream whose metadata carries an oversized artist or name tag; no authentication is required, but the victim must open or connect to the stream, so some user interaction is implied.

Exploitation

Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high (0.61275, 99.1st percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Upgrade Winamp to a version later than 5.51, which is the last affected release named in the record.
  • If upgrade is not possible, disable or remove the in_mp3.dll MP3/streaming input plug-in so Ultravox metadata is not parsed.
  • Block or restrict outbound and inbound Ultravox streaming traffic at the network perimeter where feasible.
  • Warn users not to open untrusted stream URLs or media links from unknown sources.

Detection

  • Monitor for Winamp process crashes or abnormal termination correlated with streaming media playback.
  • Inspect network traffic for Ultravox streams containing unusually long artist or name metadata fields.
  • Hunt for child processes spawned by winamp.exe, which would indicate code execution rather than a simple crash.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2008-0065 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.8CVE-2007-6403Nullsoft winamp memory buffer overflow vulnerabilityStack-based buffer overflow in Nullsoft Winamp 5.32 allows user-assisted remote attackers to execute arbitrary code via crafted unicode in a .mp4 fil…EPSS 3.4%9.5CVE-2026-88772Citrix netscaler application delivery controller memory buffer overflow vulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2008-0065), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.