CVE-2006-0681 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 4.1% (pctl 90)
Patch early
A public exploit exists.
Description
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 4.08% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-02-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| power daemon | power daemon |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Power Daemon 2.0.2 - 'WHATIDO' Remote Format String | 2006-02-10 |
References
- http://gotfault.net/research/advisory/gadv-powerd.txt
- http://secunia.com/advisories/18841
- http://www.securityfocus.com/bid/16582
- http://www.vupen.com/english/advisories/2006/0545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24713
- http://gotfault.net/research/advisory/gadv-powerd.txt
- http://secunia.com/advisories/18841
- http://www.securityfocus.com/bid/16582
- http://www.vupen.com/english/advisories/2006/0545
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24713
→ the Explorer · watch your stack · NVD