Vulnerability record · CVE-2004-2416 · published 31 December 2004
CVE-2004-2416: CCProxy logging component buffer overflow via HTTP GET
Youngzsoft · Ccproxy
The logging component of Youngzsoft CCProxy contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send a crafted request to the proxy and potentially execute arbitrary code in the context of the service. The flaw is remotely reachable and requires no credentials or user interaction.
Description
Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely exploitable without authentication, has public exploit references, and carries a very high EPSS score, though it is not in CISA KEV.
What it is
The logging component of Youngzsoft CCProxy contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send a crafted request to the proxy and potentially execute arbitrary code in the context of the service. The flaw is remotely reachable and requires no credentials or user interaction.
Impact
Successful exploitation can allow arbitrary code execution on the proxy host, giving the attacker control of the service and potentially the underlying system. Even without code execution, the overflow can crash the logging component and disrupt proxy availability.
Attack surface
The vulnerability is reached over the network through the HTTP proxy interface by sending an oversized GET request. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.
Exploitation
CVE-2004-2416 is not listed in CISA KEV, but multiple references are tagged as Exploit and EPSS reports a 30-day probability of 0.60587 (99.1st percentile), indicating a high likelihood of exploitation activity.
What to do
- Apply the vendor patch referenced in the Secunia advisory for CCProxy.
- If patching is not immediately possible, restrict access to the CCProxy HTTP listener to trusted networks or hosts.
- Place the proxy behind a filtering device that rejects abnormally long HTTP GET requests.
- Run the CCProxy service with least privilege so code execution does not yield administrative rights.
- Monitor vendor advisories for updated CCProxy releases and retire unsupported versions.
Detection
- Inspect proxy and web server logs for unusually long HTTP GET request lines or malformed request URIs.
- Monitor for crashes or restarts of the CCProxy logging component and correlate with inbound HTTP traffic.
- Use network IDS/IPS signatures for oversized HTTP GET requests targeting the proxy port.
- Alert on unexpected child processes or outbound connections originating from the CCProxy host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-2416 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-2416), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.