Vulnerability Details CVE-2004-1916
Multiple buffer overflows in LCDProc 0.4.1, and possibly other 0.4.x versions up to 0.4.4, allows remote attackers to execute arbitrary code via (1) a long invalid command to parse_all_client_messages function, or (2) long argv command to test_func_func function.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.08
EPSS Ranking 91.7%
CVSS Severity
CVSS v2 Score 7.5
Products affected by CVE-2004-1916
-
cpe:2.3:a:lcdproc:lcdproc:0.3
-
cpe:2.3:a:lcdproc:lcdproc:0.4
-
cpe:2.3:a:lcdproc:lcdproc:0.4.1_r1
-
cpe:2.3:a:lcdproc:lcdproc:4.0
-
cpe:2.3:a:lcdproc:lcdproc:4.1
-
cpe:2.3:a:lcdproc:lcdproc:4.2
-
cpe:2.3:a:lcdproc:lcdproc:4.3
-
cpe:2.3:a:lcdproc:lcdproc:4.4