Heap-based buffer overflow in in_mod.dll in Nullsoft Winamp 2.91 through 5.02 allows remote attackers to execute arbitrary code via a Fasttracker 2 (.xm) mod media file.
https://exchange.xforce.ibmcloud.com/vulnerabilities/15727
http://www.securityfocus.com/bid/10045
http://www.nextgenss.com/advisories/winampheap.txt
http://securitytracker.com/id?1009660