Back

CVE-2004-0416

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.

Published: Aug 6, 2004 Modified: Jun 16, 2026
CWE-119

CVSS Metrics

Affected Products (29)

Vendor Product Version
cvs cvs 1.10.7
cvs cvs 1.10.8
cvs cvs 1.11
cvs cvs 1.11.1
cvs cvs 1.11.1_p1
cvs cvs 1.11.2
cvs cvs 1.11.3
cvs cvs 1.11.4
cvs cvs 1.11.5
cvs cvs 1.11.6
cvs cvs 1.11.10
cvs cvs 1.11.11
cvs cvs 1.11.14
cvs cvs 1.11.15
cvs cvs 1.11.16
cvs cvs 1.12.1
cvs cvs 1.12.2
cvs cvs 1.12.5
cvs cvs 1.12.7
cvs cvs 1.12.8

…and 9 more

GitHub Security Advisory GHSA-xrvc-m3hh-hp9h

Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 13.21%

Top 4% most likely to be exploited

Threat Score 44 / 100

Data Sources

NVD EPSS GitHub