Back

CVE-2004-1373

Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.

Published: Dec 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (3)

Vendor Product Version
nullsoft shoutcast_server 1.9.4
nullsoft shoutcast_server 1.9.4
nullsoft shoutcast_server 1.9.4

GitHub Security Advisory GHSA-cx63-48hr-ggf7

Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 70.07%

Top 1% most likely to be exploited

Threat Score 61 / 100

Data Sources

NVD EPSS GitHub