Icecast is a widely embedded media streaming server whose vulnerability footprint concentrates in a single, modestly represented product deployed across internet-facing audio and broadcast infrastructure. The recurring exposure involves information-disclosure weaknesses that can expose sensitive configuration or stream metadata to unauthorized actors, and vulnerabilities affecting the product frequently acquire public exploit code. Defenders should track this vendor's releases for streaming deployments and treat exposed instances as patching priorities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Icecast over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-1561HIGH Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with a large number of headers. | Dec 31, 2004 | 7.5 | 83 | NO | YES |
CVE-2001-0197HIGH Format string vulnerability in print_client in icecast 1.3.8beta2 and earlier allows remote attackers to execute arbitrary commands. | Mar 26, 2001 | 10.0 | 41 | NO | YES |
CVE-2005-0838HIGH Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possibly execute arbitrary code via (1) a long test value in an xs | May 2, 2005 | 7.5 | 32 | NO | YES |
CVE-2002-0177HIGH Buffer overflows in icecast 1.3.11 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request from an MP3 client. | Apr 22, 2002 | 7.5 | 32 | NO | YES |
CVE-2001-0784MEDIUM Directory traversal vulnerability in Icecast 1.3.10 and earlier allows remote attackers to read arbitrary files via a modified .. (dot dot) attack using encoded URL characters. | Oct 18, 2001 | 5.0 | 26 | NO | YES |
CVE-2001-1083MEDIUM Icecast 1.3.7, and other versions before 1.3.11 with HTTP server file streaming support enabled allows remote attackers to cause a denial of service (crash) via a URL that ends in | Jun 26, 2001 | 5.0 | 26 | NO | YES |
CVE-2002-1982MEDIUM Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, | Dec 31, 2002 | 5.0 | 23 | NO | YES |
CVE-2001-1230HIGH Buffer overflows in Icecast before 1.3.10 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | Mar 13, 2001 | 7.5 | 20 | NO | NO |
CVE-2001-1229HIGH Buffer overflows in (1) Icecast before 1.3.9 and (2) libshout before 1.0.4 allow remote attackers to cause a denial of service (crash) and execute arbitrary code. | Mar 12, 2001 | 7.5 | 20 | NO | NO |
CVE-2014-9018MEDIUM Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors. | Dec 3, 2014 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Icecast.
Media articles that mention a CVE ID that affects a product developed by Icecast — matched by CVE ID, not by vendor name.