Nullsoft maintains a compact but historically prominent portfolio centered on media playback and streaming software, with Winamp and SHOUTcast Server serving as widely recognized applications in audio distribution and internet radio. Despite the modest product count, the vendor's vulnerability footprint reflects its legacy prominence and the complexity of media processing and web-facing components, with disclosures spanning memory-safety issues, input validation weaknesses, code injection risks, and cross-site scripting vulnerabilities across its product line. The vendor's vulnerabilities frequently acquire public exploit code, making patches for this software a practical priority for defenders where Winamp or SHOUTcast instances remain deployed. The recurring weakness classes—particularly buffer-boundary violations, input-handling flaws, and code-injection pathways—are characteristic of both native media codecs and web-integrated features that have historically been sources of reliable exploitation primitives. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nullsoft over time
Signals from CVEs in this vendor scope (78 CVEs).
78 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0476HIGH Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field). | Jan 31, 2006 | 7.6 | 78 | NO | YES |
CVE-2004-1373HIGH Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a | Dec 23, 2004 | 7.5 | 74 | NO | YES |
CVE-2009-1831HIGH The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an i | May 29, 2009 | 9.3 | 63 | NO | YES |
CVE-2009-0263HIGH Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) he | Jan 23, 2009 | 10.0 | 48 | NO | YES |
CVE-2004-1119HIGH Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist | Jan 10, 2005 | 10.0 | 43 | NO | YES |
CVE-2010-3137HIGH Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct | Aug 26, 2010 | 9.3 | 40 | NO | YES |
CVE-2010-4371HIGH Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box. | Dec 2, 2010 | 9.3 | 39 | NO | YES |
CVE-2006-5567HIGH Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to | Oct 27, 2006 | 9.3 | 39 | NO | YES |
CVE-2005-2310HIGH Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1 | Jul 19, 2005 | 9.3 | 39 | NO | YES |
CVE-2006-3228HIGH Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file. | Jun 26, 2006 | 9.3 | 38 | NO | YES |
Signals from CVEs in this vendor scope (78 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nullsoft.
Media articles that mention a CVE ID that affects a product developed by Nullsoft — matched by CVE ID, not by vendor name.