peter bassill · operator
$ cve CVE-2004-0354 JSON

CVE-2004-0354 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 15.6% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS15.64% — more likely to be exploited than 97% of all CVEs
On CISA KEVno
Public exploityes
Published2004-11-23
Last modified2026-06-16

Affected (1)

VendorProduct
gnuanubis

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD