7.5
CVE-2004-0159
- EPSS 9.02%
- Veröffentlicht 15.03.2004 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:05:03
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Samhain Labs ≫ Hsftp Version1.4
Samhain Labs ≫ Hsftp Version1.5
Samhain Labs ≫ Hsftp Version1.6
Samhain Labs ≫ Hsftp Version1.7
Samhain Labs ≫ Hsftp Version1.9
Samhain Labs ≫ Hsftp Version1.10
Samhain Labs ≫ Hsftp Version1.11
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 9.02% | 0.946 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://lists.grok.org.uk/pipermail/full-disclosure/2004-February/017737.html
http://www.osvdb.org/4029
http://www.securityfocus.com/bid/9715
https://exchange.xforce.ibmcloud.com/vulnerabilities/15276
https://www.debian.org/security/2004/dsa-447