CVE-2004-0247
Status: ModifiedMedium (5)—💥 Exploit
The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P
- Base score: 5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 3.44%
- Percentile among all scored CVEs: 89
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Cauldron Chaser 1.4/1.5 - Remote Denial of Service (1) (2/3/2004)
- Published on Exploit-DB · Cauldron Chaser 1.4/1.5 - Remote Denial of Service (2) (2/3/2004)
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2004-0247",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2004-11-23T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=107584109420084&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/9567",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15031",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=107584109420084&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/9567",
"tags": [
"Exploit",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/15031",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The client and server of Chaser 1.50 and earlier allow remote attackers to cause a denial of service (crash via exception) via a UDP packet with a length field that is greater than the actual data length, which causes Chaser to read unexpected memory."
},
{
"lang": "es",
"value": "El cliente y el servidor de Chaser 1.50 y anteriores permite que atacantes remotos provoquen una denegación de servicio (caída) mediante un paquete UDP con un campo de longitud que es mayor que la longitud real de los datos (lo que provoca leer memoria inexperadamente)."
}
],
"lastModified": "2026-06-16T22:05:14.997",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cauldron:chaser_client:1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0092E5FF-5978-4DD7-A1E3-CB9F3D640754"
},
{
"criteria": "cpe:2.3:a:cauldron:chaser_server:1.4.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FC5912C4-EBE1-4928-BC62-2E39B4E1417F"
},
{
"criteria": "cpe:2.3:a:cauldron:chaser_server:1.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "49C5DD74-599D-4D6A-91A0-233380B00C4B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}