Back

CVE-2004-0733

Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.

Published: Jul 27, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (4)

Vendor Product Version
ollydbg ollydbg 1.0.6
ollydbg ollydbg 1.0.8b
ollydbg ollydbg 1.0.9
ollydbg ollydbg 1.10

GitHub Security Advisory GHSA-27p7-xph2-64m7

Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service ...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 5.07%

Top 8% most likely to be exploited

Threat Score 31.5 / 100

Data Sources

NVD EPSS GitHub