Lucene search

K
nvd[email protected]NVD:CVE-2004-1946
HistoryApr 19, 2004 - 4:00 a.m.

CVE-2004-1946

2004-04-1904:00:00
web.nvd.nist.gov
1

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

20.8%

Format string vulnerability in the PRINT_ERROR function in common.c for Cherokee Web Server 0.4.16 and earlier allows local users to execute arbitrary code via format string specifiers in the -C command line argument. NOTE: it is not clear whether this issue could be exploited remotely, or if Cherokee is running at escalated privileges. Therefore it might not be a vulnerability.

Affected configurations

Nvd
Node
cherokeecherokee_httpdMatch0.4.16
VendorProductVersionCPE
cherokeecherokee_httpd0.4.16cpe:2.3:a:cherokee:cherokee_httpd:0.4.16:*:*:*:*:*:*:*

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.3

Confidence

High

EPSS

0.001

Percentile

20.8%

Related for NVD:CVE-2004-1946