Back

CVE-2004-2386

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and earlier allows remote attackers to execute arbitrary code via format string specifiers passed from the HandleCPCCommand function.

Published: Dec 31, 2004 Modified: Jun 16, 2026
CWE-134

CVSS Metrics

Affected Products (9)

Vendor Product Version
denis_sbragion sredird 1.0
denis_sbragion sredird 1.1.6
denis_sbragion sredird 1.1.7
denis_sbragion sredird 1.1.8
denis_sbragion sredird 2.0
denis_sbragion sredird 2.1
denis_sbragion sredird 2.2
denis_sbragion sredird 2.2.1
peter_astrand sercd 2.3.0

GitHub Security Advisory GHSA-9hxf-7mx9-m3j2

Format string vulnerability in the LogMsg function in sercd before 2.3.1 and sredird 2.2.1 and...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.21%

Top 13% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub