Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2004-0238

29
FAUCET Score

CVE-2004-0238 describes multiple buffer overflow vulnerabilities in Overkill (0verkill) 0.15pre3. These flaws could allow local users to execute arbitrary code in the client via a long HOME environment variable, and potentially remote attackers to execute arbitrary code through long strings in the send_message function or the server's parse_command_line function. With a CVSS score of 7.2, this vulnerability is considered high severity, indicating a local attack vector with low complexity and complete compromise of confidentiality, integrity, and availability. Its EPSS score is low, suggesting a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, nor is it listed in CISA's KEV catalog. While an ExploitDB entry exists for a similar version (0.16), there are no Metasploit or Nuclei modules, and community discussion and media coverage are virtually nonexistent.

Impacted Technologies

VendorProductVersion(s)CPE
0.16CPE matchmatch criteria
cpe:2.3:a:0verkill:0verkill:0.16:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
5.16%
Probability of exploitation in next 30 days
EPSS Percentile
91.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-23634 · Feb 2, 2004
This CVE's current EPSS score of 0.0516 is in the 98th percentile among its peer group of 3,237 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

lists.grok.org.uk / pipermail/full-disclosure/2004-February/016579.html
marc.info
exchange.xforce.ibmcloud.com / vulnerabilities/14999
exchange.xforce.ibmcloud.com / vulnerabilities/15000
securiteam.com / securitynews/5AP010KC0C.html
securityfocus.com / bid/9550
ExploitVendor Advisory