← Vulnerability feed

Vulnerability record · CVE-2004-1184 · published 21 January 2005

CVE-2004-1184: Gnu enscript vulnerability

Gnu · Enscript

The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

4.6 CVSS 2.0 Medium EPSS 1.2% · top 33.5%
4.6CVSS 2.0 base score
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
32References
16 Jun 2026Last modified by NVD

Description

The EPSF pipe support in enscript 1.6.3 allows remote attackers or local users to execute arbitrary commands via shell metacharacters.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/35074
http://securitytracker.com/id?1012965
http://support.apple.com/kb/HT3549
http://www.debian.org/security/2005/dsa-654 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:033
http://www.redhat.com/support/errata/RHSA-2005-040.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/419768/100/0/threaded
http://www.securityfocus.com/archive/1/435199/100/0/threaded
http://www.securityfocus.com/bid/12329
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2009/1297
https://exchange.xforce.ibmcloud.com/vulnerabilities/19012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9658
https://usn.ubuntu.com/68-1/
http://lists.apple.com/archives/security-announce/2009/May/msg00002.html
http://secunia.com/advisories/35074
http://securitytracker.com/id?1012965
http://support.apple.com/kb/HT3549
http://www.debian.org/security/2005/dsa-654 PatchVendor Advisory
http://www.gentoo.org/security/en/glsa/glsa-200502-03.xml PatchVendor Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:033
http://www.redhat.com/support/errata/RHSA-2005-040.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/419768/100/0/threaded
http://www.securityfocus.com/archive/1/435199/100/0/threaded
http://www.securityfocus.com/bid/12329
http://www.us-cert.gov/cas/techalerts/TA09-133A.html US Government Resource
http://www.vupen.com/english/advisories/2009/1297
https://exchange.xforce.ibmcloud.com/vulnerabilities/19012
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9658
https://usn.ubuntu.com/68-1/

Track CVE-2004-1184 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-4074Centre for speech technology research gentoo linux vulnerabilityThe default configuration of Centre for Speech Technology Research (CSTR) Festival 1.95 beta (aka 2.0 beta) on Gentoo Linux, SUSE Linux, and possibly…EPSS 5.4%10.0CVE-2007-0460Suse linux memory buffer overflow vulnerabilityMultiple buffer overflows in ulogd for SUSE Linux 9.3 up to 10.1, and possibly other distributions, have unknown impact and attack vectors related to…EPSS 2.6%10.0CVE-2006-6235Gnu privacy guard vulnerabilityA "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary c…EPSS 5.9%10.0CVE-2006-5616Openpbs vulnerabilityMultiple unspecified vulnerabilities in OpenPBS, as used in SUSE Linux 9.2 through 10.1, allow attackers to execute arbitrary code via unspecified ve…EPSS 3.5%10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2005-2023Suse linux vulnerabilityThe send_pinentry_environment function in asshelp.c in gpg2 on SUSE Linux 9.3 does not properly handle certain options, which can prevent pinentry fr…EPSS 2.3%10.0CVE-2004-0989Xmlsoft libxml vulnerabilityMultiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code vi…EPSS 22%10.0CVE-2004-0990Gd graphics library gdlib vulnerabilityInteger overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and …EPSS 28%

Source: NIST National Vulnerability Database (record CVE-2004-1184), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.