Nullsoft / Shoutcast Server
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-1229 | Cross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the top-level… | MEDIUM | 4.3 | Mar 2, 2007 |
| CVE-2006-3534 | Directory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote attackers t… | HIGH | 7.8 | Jul 12, 2006 |
| CVE-2006-3007 | Multiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ fields (1) Desc… | MEDIUM | 4.3 | Jun 13, 2006 |
| CVE-2003-1174 | Buffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or (2) icy-u… | LOW | 2.1 | May 10, 2005 |
| CVE-2004-1373 | Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format s… | HIGH | 7.5 | Jan 19, 2005 |
| CVE-2002-1470 | SHOUTcast 1.8.9 and earlier allows local users to obtain the cleartext administrative password via a GET request to port 8001, which causes the password to be… | LOW | 2.1 | Mar 18, 2003 |
| CVE-2002-0907 | Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value i… | HIGH | 7.5 | Aug 31, 2002 |
| CVE-2002-0199 | Buffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a… | HIGH | 7.5 | May 3, 2002 |
| CVE-2001-1304 | Buffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user-agent or… | MEDIUM | 5.0 | May 3, 2002 |
| CVE-1999-1561 | Nullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to gain admini… | HIGH | 7.2 | Sep 12, 2001 |
Showing 1 to 10 of 10 CVEs