Back
CVE-2004-0448
Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote authenticated users to execute arbitrary code via format string specifiers in certain syslog messages.
Published: Dec 6, 2004
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (4)
| Vendor | Product | Version |
|---|---|---|
| jftpgw | jftpgw | 0.13 |
| jftpgw | jftpgw | 0.13.1 |
| jftpgw | jftpgw | 0.13.2 |
| jftpgw | jftpgw | 0.13.3 |
GitHub Security Advisory GHSA-3m3c-pvwf-4p64
Format string vulnerability in the log function for jftpgw 0.13.4 and earlier allows remote...
References (6)
- http://www.debian.org/security/2004/dsa-510 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10438 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16271
- http://www.debian.org/security/2004/dsa-510 Patch, Vendor Advisory
- http://www.securityfocus.com/bid/10438 Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16271
Risk Scores
CVSS Score
10.0 / 10
EPSS Score
4.34%
Top 10% most likely to be exploited
Threat Score
41.3 / 100
Data Sources
NVD
EPSS
GitHub