Back

CVE-2004-0159

Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of service and possibly execute arbitrary code via file names containing format string characters that are not properly handled when executing an "ls" command.

Published: Mar 15, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (7)

Vendor Product Version
samhain_labs hsftp 1.4
samhain_labs hsftp 1.5
samhain_labs hsftp 1.6
samhain_labs hsftp 1.7
samhain_labs hsftp 1.9
samhain_labs hsftp 1.10
samhain_labs hsftp 1.11

GitHub Security Advisory GHSA-7v4p-3v84-r8mc

Format string vulnerability in hsftp 1.11 allows remote authenticated users to cause a denial of...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 9.02%

Top 5% most likely to be exploited

Threat Score 32.7 / 100

Data Sources

NVD EPSS GitHub