← Vulnerability feed

Vulnerability record · CVE-2004-2416 · published 31 December 2004

CVE-2004-2416: CCProxy logging component buffer overflow via HTTP GET

Youngzsoft · Ccproxy

The logging component of Youngzsoft CCProxy contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send a crafted request to the proxy and potentially execute arbitrary code in the context of the service. The flaw is remotely reachable and requires no credentials or user interaction.

7.5 CVSS 2.0 High EPSS 61% · top 0.9%
7.5CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the logging component of CCProxy allows remote attackers to execute arbitrary code via a long HTTP GET request.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication, has public exploit references, and carries a very high EPSS score, though it is not in CISA KEV.

What it is

The logging component of Youngzsoft CCProxy contains a buffer overflow that is triggered by a long HTTP GET request. A remote, unauthenticated attacker can send a crafted request to the proxy and potentially execute arbitrary code in the context of the service. The flaw is remotely reachable and requires no credentials or user interaction.

Impact

Successful exploitation can allow arbitrary code execution on the proxy host, giving the attacker control of the service and potentially the underlying system. Even without code execution, the overflow can crash the logging component and disrupt proxy availability.

Attack surface

The vulnerability is reached over the network through the HTTP proxy interface by sending an oversized GET request. No authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

CVE-2004-2416 is not listed in CISA KEV, but multiple references are tagged as Exploit and EPSS reports a 30-day probability of 0.60587 (99.1st percentile), indicating a high likelihood of exploitation activity.

What to do

  • Apply the vendor patch referenced in the Secunia advisory for CCProxy.
  • If patching is not immediately possible, restrict access to the CCProxy HTTP listener to trusted networks or hosts.
  • Place the proxy behind a filtering device that rejects abnormally long HTTP GET requests.
  • Run the CCProxy service with least privilege so code execution does not yield administrative rights.
  • Monitor vendor advisories for updated CCProxy releases and retire unsupported versions.

Detection

  • Inspect proxy and web server logs for unusually long HTTP GET request lines or malformed request URIs.
  • Monitor for crashes or restarts of the CCProxy logging component and correlate with inbound HTTP traffic.
  • Use network IDS/IPS signatures for oversized HTTP GET requests targeting the proxy port.
  • Alert on unexpected child processes or outbound connections originating from the CCProxy host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2416 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2004-2416), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.