Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-0006

27
FAUCET Score

CVE-2004-0006 describes multiple buffer overflow vulnerabilities in Gaim 0.75 and earlier, and Ultramagnetic before 0.81. These flaws allow remote attackers to trigger denial of service and potentially execute arbitrary code through various vectors, including malformed Yahoo web connection cookies, long parameters in Yahoo login pages, YMSG packets, URL parsing, and HTTP proxy connections. The vulnerability has a CVSS score of 7.5, indicating high severity with a network attack vector, low attack complexity, and potential for partial confidentiality, integrity, and availability impact. Its FAUCET Risk Score is 94/100, highlighting significant risk. Despite its age, there is no evidence of active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. However, the vulnerability has garnered significant community discussion with 10 mentions, suggesting ongoing interest or analysis.

Impacted Technologies

VendorProductVersion(s)CPE
<= 0.75CPE matchmatch criteria
cpe:2.3:a:rob_flynn:gaim:*:*:*:*:*:*:*:*
<= 0.81CPE matchmatch criteria
cpe:2.3:a:ultramagnetic:ultramagnetic:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.5HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.61%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0761 is in the 90th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux AS (Advanced Server) version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux ES version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux WS version 2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux 9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Linux Advanced Workstation 2.1
View patch
gentoovendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2004-0006Moderate

security flaw

Jan 26, 2004

References

patches.sgi.com / support/free/security/advisories/20040201-01-U.asc
patches.sgi.com / support/free/security/advisories/20040202-01-U.asc
archives.neohapsis.com / archives/fulldisclosure/2004-01/0994.html
distro.conectiva.com.br / atualizacoes
marc.info
marc.info
security.e-matters.de / advisories/012004.html
PatchVendor Advisory
security.gentoo.org / glsa/glsa-200401-04.xml
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/14939
exchange.xforce.ibmcloud.com / vulnerabilities/14940
exchange.xforce.ibmcloud.com / vulnerabilities/14941
exchange.xforce.ibmcloud.com / vulnerabilities/14943
exchange.xforce.ibmcloud.com / vulnerabilities/14945
exchange.xforce.ibmcloud.com / vulnerabilities/14947
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10222
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A818
ultramagnetic.sourceforge.net / advisories/001.html
PatchVendor Advisory
debian.org / security/2004/dsa-434
kb.cert.org / vuls/id/297198
US Government Resource
kb.cert.org / vuls/id/371382
US Government Resource
kb.cert.org / vuls/id/444158
US Government Resource
kb.cert.org / vuls/id/503030
US Government Resource
kb.cert.org / vuls/id/527142
US Government Resource
kb.cert.org / vuls/id/871838
US Government Resource
mandriva.com / security/advisories
novell.com / linux/security/advisories/2004_04_gaim.html
osvdb.org / 3731
osvdb.org / 3732
redhat.com / support/errata/RHSA-2004-032.html
PatchVendor Advisory
redhat.com / support/errata/RHSA-2004-033.html
redhat.com / support/errata/RHSA-2004-045.html
securityfocus.com / bid/9489
securitytracker.com / id
slackware.com / security/viewer.php