Back

CVE-2004-1192

Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute arbitrary code via format string specifiers sent to the server.

Published: Jan 10, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (6)

Vendor Product Version
citadel ux 6.07
citadel ux 6.08
citadel ux 6.23
citadel ux 6.24
citadel ux 6.26
citadel ux 6.27

GitHub Security Advisory GHSA-cv96-99r4-547h

Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote...

Risk Scores

CVSS Score 10.0 / 10
EPSS Score 11.75%

Top 4% most likely to be exploited

Threat Score 43.5 / 100

Data Sources

NVD EPSS GitHub