peter bassill · operator
$ cve CVE-2005-0226 JSON

CVE-2005-0226 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

Format string vulnerability in the Log_Resolver function in log.c for ngIRCd 0.8.2 and earlier, when compiled with IDENT, logging to SYSLOG, and with DEBUG enabled, allows remote attackers to execute arbitrary code.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.9% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-02-03
Last modified2026-06-16

Affected (1)

VendorProduct
ngircdngircd

Public exploits

SourceTitleDate
exploit-dbngIRCd 0.8.2 - Remote Format String2005-02-03

References

→ the Explorer  ·  watch your stack  ·  NVD