VYPR
Unrated severityNVD Advisory· Published Aug 14, 2006· Updated Apr 16, 2026

CVE-2006-4127

CVE-2006-4127

Description

Multiple format string vulnerabilities in DConnect Daemon 0.7.0 and earlier allow remote administrators to execute arbitrary code via format string specifiers that are not properly handled when calling the (1) privmsg() or (2) pubmsg functions from (a) cmd.user.c, (b) penalties.c, or (c) cmd.dc.c.

Affected products

3
  • cpe:2.3:a:dconnect:dconnect_daemon:0.0.2:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:dconnect:dconnect_daemon:0.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:dconnect:dconnect_daemon:0.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:dconnect:dconnect_daemon:0.7.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

9

News mentions

0

No linked articles in our index yet.