Back

CVE-2004-2074

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string specifiers in the (1) PASS or (2) RETR commands.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
bolintech dream_ftp_server 1.02

GitHub Security Advisory GHSA-3qh7-hqp3-w27g

Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service ...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 35.78%

Top 2% most likely to be exploited

Threat Score 30.7 / 100

Data Sources

NVD EPSS GitHub