CVE-2004-0007

Buffer overflow in the Extract Info Field Function for (1) MSN and (2) YMSG protocol handlers in Gaim 0.74 and earlier, and Ultramagnetic before 0.81, allows remote attackers to cause a denial of service and possibly execute arbitrary code.

Published: 2004-03-03 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2004-0007 is rated Moderate Risk (64.8/100): CVSS High severity, with high exploitation likelihood (EPSS 26.44%, 96th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +1.11% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2004-0007

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-01-23 25.33% 26.44% +1.11%
2 2025-10-03 24.40% 25.33% +0.93%
3 2025-03-30 24.40%

Full EPSS history (10 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2004-0007

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.5 2.0 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
10.0 6.4 [email protected]

Weakness enumeration for CVE-2004-0007

OS Trackers for CVE-2004-0007

vendor priority summary link
redhat medium https://access.redhat.com/security/cve/CVE-2004-0007

Affected software / configurations for CVE-2004-0007

Vendor Product Version Raw CPE
rob_flynn gaim <= 0.74 cpe:2.3:a:rob_flynn:gaim:*:*:*:*:*:*:*:*
ultramagnetic ultramagnetic <= 0.81 cpe:2.3:a:ultramagnetic:ultramagnetic:*:*:*:*:*:*:*:*

References for CVE-2004-0007

URL Tags
http://archives.neohapsis.com/archives/fulldisclosure/2004-01/0994.html
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000813
http://marc.info/?l=bugtraq&m=107513690306318&w=2
http://marc.info/?l=bugtraq&m=107522432613022&w=2
http://security.e-matters.de/advisories/012004.html Patch Vendor Advisory
http://security.gentoo.org/glsa/glsa-200401-04.xml
http://ultramagnetic.sourceforge.net/advisories/001.html Patch Vendor Advisory
http://www.debian.org/security/2004/dsa-434 Patch Vendor Advisory
http://www.kb.cert.org/vuls/id/197142 US Government Resource
http://www.mandriva.com/security/advisories?name=MDKSA-2004:006
http://www.osvdb.org/3733
http://www.redhat.com/support/errata/RHSA-2004-032.html
http://www.redhat.com/support/errata/RHSA-2004-033.html Patch Vendor Advisory
http://www.securityfocus.com/advisories/6281
http://www.securityfocus.com/bid/9489
http://www.securitytracker.com/id?1008850
http://www.slackware.com/security/viewer.php?l=slackware-security&y=2004&m=slackware-security.361158
https://exchange.xforce.ibmcloud.com/vulnerabilities/14946
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A819
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9906
cvelogic Threat Intelligence