Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nullsoft

First CVE: Aug 20, 1999Active for: 27 yearsTotal CVEs: 78
55.9
VTI Score
TOP TARGET

Nullsoft maintains a compact but historically prominent portfolio centered on media playback and streaming software, with Winamp and SHOUTcast Server serving as widely recognized applications in audio distribution and internet radio. Despite the modest product count, the vendor's vulnerability footprint reflects its legacy prominence and the complexity of media processing and web-facing components, with disclosures spanning memory-safety issues, input validation weaknesses, code injection risks, and cross-site scripting vulnerabilities across its product line. The vendor's vulnerabilities frequently acquire public exploit code, making patches for this software a practical priority for defenders where Winamp or SHOUTcast instances remain deployed. The recurring weakness classes—particularly buffer-boundary violations, input-handling flaws, and code-injection pathways—are characteristic of both native media codecs and web-integrated features that have historically been sources of reliable exploitation primitives. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
78
Total CVEs
More Total CVEs than 99% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 74% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 53% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nullsoft over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 20, 1999
26 years ago
Most Recent CVE
Apr 24, 2026
91 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (78 CVEs).

78 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2006-0476HIGH
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).
Jan 31, 20067.678NOYES
CVE-2004-1373HIGH
Format string vulnerability in SHOUTcast 1.9.4 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via format string specifiers in a
Dec 23, 20047.574NOYES
CVE-2009-1831HIGH
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute arbitrary code via a crafted MAKI file, which triggers an i
May 29, 20099.363NOYES
CVE-2009-0263HIGH
Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a large Common Chunk (COMM) he
Jan 23, 200910.048NOYES
CVE-2004-1119HIGH
Stack-based buffer overflow in IN_CDDA.dll in Winamp 5.05, and possibly other versions including 5.06, allows remote attackers to execute arbitrary code via a certain .m3u playlist
Jan 10, 200510.043NOYES
CVE-2010-3137HIGH
Untrusted search path vulnerability in Nullsoft Winamp 5.581, and probably other versions, allows local users, and possibly remote attackers, to execute arbitrary code and conduct
Aug 26, 20109.340NOYES
CVE-2010-4371HIGH
Buffer overflow in the in_mod plugin in Winamp before 5.6 allows remote attackers to have an unspecified impact via vectors related to the comment box.
Dec 2, 20109.339NOYES
CVE-2006-5567HIGH
Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to
Oct 27, 20069.339NOYES
CVE-2005-2310HIGH
Buffer overflow in Winamp 5.03a, 5.09 and 5.091, and other versions before 5.094, allows remote attackers to execute arbitrary code via an MP3 file with a long ID3v2 tag such as (1
Jul 19, 20059.339NOYES
CVE-2006-3228HIGH
Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.
Jun 26, 20069.338NOYES
View all 78 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products78 CVEs
24%
68%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local4 (5.1%)
Network1 (1.3%)
Unknown73 (93.6%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (5.1%)
High1 (1.3%)
Unknown73 (93.6%)
User Interaction
None3 (3.8%)
Unknown73 (93.6%)
Required2 (2.6%)
Privileges Required
Low1 (1.3%)
High0 (0.0%)
None4 (5.1%)
Unknown73 (93.6%)

Exploit Exposure

Signals from CVEs in this vendor scope (78 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
3.8% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
26 CVEs
33.3% of CVEs· 79th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nullsoft.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nullsoft — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nullsoft's Products

View all 1 CNAs →

Top CWEs