Back

CVE-2004-0277

Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the username.

Published: Nov 23, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
bolintech dream_ftp_server 1.02

GitHub Security Advisory GHSA-62j2-7hqq-4gqf

Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 13.58%

Top 4% most likely to be exploited

Threat Score 44.1 / 100

Data Sources

NVD EPSS GitHub