← All CVEs

CVE-2004-2299

high · 7.5

Buffer overflow in Omnicron OmniHTTPd 3.0a and earlier allows remote attackers to execute arbitrary code via an HTTP GET request with a long Range header.

7.5
CVSS
10.2%
EPSS (exploit prob.)
95th
EPSS percentile
2004-12-31
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
omnicronomnihttpd1.1
omnicronomnihttpd2.0.4
omnicronomnihttpd2.0.5
omnicronomnihttpd2.0.6
omnicronomnihttpd2.0.7
omnicronomnihttpd2.0.8
omnicronomnihttpd2.0_9
omnicronomnihttpd2.0_alpha_1
omnicronomnihttpd2.0_alpha_2
omnicronomnihttpd2.4_pro
omnicronomnihttpd2.10
omnicronomnihttpd3.0a

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-2299