CVE-2004-0354 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 15.6% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple format string vulnerabilities in GNU Anubis 3.6.0 through 3.6.2, 3.9.92 and 3.9.93 allow remote attackers to execute arbitrary code via format string specifiers in strings passed to (1) the info function in log.c, (2) the anubis_error function in errs.c, or (3) the ssl_error function in ssl.c.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 15.64% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-11-23 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| gnu | anubis |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | GNU Anubis 3.6.x/3.9.x - Multiple Format String Vulnerabilities | 2004-03-01 |
References
- http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
- http://marc.info/?l=bugtraq&m=107843915424588&w=2
- http://www.securityfocus.com/bid/9772
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15346
- http://mail.gnu.org/archive/html/bug-anubis/2004-02/msg00000.html
- http://marc.info/?l=bugtraq&m=107843915424588&w=2
- http://www.securityfocus.com/bid/9772
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15346
→ the Explorer · watch your stack · NVD