AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2004-1097

HIGH · CVSS 10 EPSS 5.56%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2005-01-10 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2004-1097
Severity
HIGH
CVSS
10
EPSS
5.56%

Original NVD Description

Format string vulnerability in the cherokee_logger_ncsa_write_string function in Cherokee 0.4.17 and earlier, when authenticating via auth_pam, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via format string specifiers in the URL.