← Vulnerability feed

Vulnerability record · CVE-2002-0907 · published 4 October 2002

CVE-2002-0907: Nullsoft shoutcast server vulnerability

Nullsoft · Shoutcast Server

Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".

7.5 CVSS 2.0 High EPSS 5.6% · top 7.3%
7.5CVSS 2.0 base score
5.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrary code on the server via a long value in a header whose name begins with "icy-".

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2002-0907 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2006-3534Nullsoft shoutcast server vulnerabilityDirectory traversal vulnerability in Nullsoft SHOUTcast DSP before 1.9.6 filters directory traversal sequences before decoding, which allows remote a…EPSS 2.5%7.5CVE-2004-1373SHOUTcast format string flaw allows code executionSHOUTcast 1.9.4 contains a format string vulnerability reachable through format specifiers placed in a content URL, demonstrated via the filename por…EPSS 70%analysed7.5CVE-2002-0199Nullsoft shoutcast server vulnerabilityBuffer overflow in admin.cgi for Nullsoft Shoutcast Server 1.8.3 allows remote attackers to cause a denial of service and possibly execute arbitrary …EPSS 3.4%7.2CVE-1999-1561Nullsoft shoutcast server vulnerabilityNullsoft SHOUTcast server stores the administrative password in plaintext in a configuration file (sc_serv.conf), which could allow a local user to g…EPSS 0.35%5.0CVE-2001-1304Nullsoft shoutcast server vulnerabilityBuffer overflow in SHOUTcast Server 1.8.2 allows remote attackers to cause a denial of service (crash) via several HTTP requests with a long (1) user…EPSS 1.9%4.3CVE-2007-1229Nullsoft shoutcast server cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in the Nullsoft ShoutcastServer 1.9.7 allows remote attackers to inject arbitrary web script or HTML via the…EPSS 1.8%4.3CVE-2006-3007Nullsoft shoutcast server vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in SHOUTcast 1.9.5 allow remote attackers to inject arbitrary HTML or web script via the DJ field…EPSS 2.0%2.1CVE-2003-1174Nullsoft shoutcast server vulnerabilityBuffer overflow in NullSoft Shoutcast Server 1.9.2 allows local users to cause a denial of service via (1) icy-name followed by a long server name or…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2002-0907), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.