← Vulnerability feed

Vulnerability record · CVE-2004-2394 · published 31 December 2004

CVE-2004-2394: Mandrakesoft mandrake multi network firewall vulnerability

MMandrakesoft · Mandrake Multi Network Firewall

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

2.1 CVSS 2.0 Low EPSS 0.36% · top 72.5%
2.1CVSS 2.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Off-by-one error in passwd 0.68 and earlier, when using the --stdin option, causes passwd to use the first 78 characters of a password instead of the first 79, which results in a small reduction of the search space required for brute force attacks.

AV:L/AC:L/Au:N/C:N/I:P/A:N

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-1188Mplayer vulnerabilityThe pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the c…EPSS 2.0%10.0CVE-2004-1187Mplayer vulnerabilityHeap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote at…EPSS 5.2%10.0CVE-2004-0460ISC DHCP dhcpd logging buffer overflow via hostname optionsISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQ…EPSS 45%analysed10.0CVE-2004-0461Infoblox dns one appliance vulnerabilityThe DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C includ…EPSS 17%10.0CVE-2004-0386Mplayer vulnerabilityBuffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Locat…EPSS 27%10.0CVE-2003-0041Mit kerberos ftp client os command injection vulnerabilityKerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.EPSS 3.5%10.0CVE-2001-0388Freebsd vulnerabilitytime server daemon timed allows remote attackers to cause a denial of service via malformed packets.EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2004-2394), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.