Unrated severityNVD Advisory· Published Dec 23, 2004· Updated Apr 16, 2026
CVE-2004-1373
CVE-2004-1373
Description
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a content URL, as demonstrated in the filename portion of a .mp3 file.
Affected products
3cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:linux:*:*:*:*:*+ 2 more
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:linux:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:mac_os_x:*:*:*:*:*
- cpe:2.3:a:nullsoft:shoutcast_server:1.9.4:*:win32:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.