{"api_version":"1","generated_at":"2026-07-23T05:01:34+00:00","cve":"CVE-2004-1033","urls":{"html":"https://cve.report/CVE-2004-1033","api":"https://cve.report/api/cve/CVE-2004-1033.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2004-1033","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2004-1033"},"summary":{"title":"CVE-2004-1033","description":"Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-03-01 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://security.gentoo.org/glsa/glsa-200411-27.xml","name":"http://security.gentoo.org/glsa/glsa-200411-27.xml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gentoo Linux Documentation\n--\n  Fcron: Multiple vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/11684","name":"http://www.securityfocus.com/bid/11684","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Fcron FCronTab/FCronSighUp Multiple Local Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false","name":"http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18078","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18078","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2004-1033","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2004-1033","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2004","cve_id":"1033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"gentoo","cpe5":"linux","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"thibault_godouet","cpe5":"fcron","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2004","cve_id":"1033","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"thibault_godouet","cpe5":"fcron","cpe6":"2.9.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T00:39:00.608Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20041115 Multiple Security Vulnerabilities in Fcron","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false"},{"name":"11684","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/11684"},{"name":"GLSA-200411-27","tags":["vendor-advisory","x_refsource_GENTOO","x_transferred"],"url":"http://security.gentoo.org/glsa/glsa-200411-27.xml"},{"name":"fcron-fcrontab-obtain-info(18078)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18078"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2004-11-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-10T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20041115 Multiple Security Vulnerabilities in Fcron","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false"},{"name":"11684","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/11684"},{"name":"GLSA-200411-27","tags":["vendor-advisory","x_refsource_GENTOO"],"url":"http://security.gentoo.org/glsa/glsa-200411-27.xml"},{"name":"fcron-fcrontab-obtain-info(18078)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18078"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2004-1033","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20041115 Multiple Security Vulnerabilities in Fcron","refsource":"IDEFENSE","url":"http://www.idefense.com/application/poi/display?id=157&type=vulnerabilities&flashstatus=false"},{"name":"11684","refsource":"BID","url":"http://www.securityfocus.com/bid/11684"},{"name":"GLSA-200411-27","refsource":"GENTOO","url":"http://security.gentoo.org/glsa/glsa-200411-27.xml"},{"name":"fcron-fcrontab-obtain-info(18078)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/18078"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2004-1033","datePublished":"2004-11-24T05:00:00.000Z","dateReserved":"2004-11-12T00:00:00.000Z","dateUpdated":"2024-08-08T00:39:00.608Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-03-01 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:N/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:thibault_godouet:fcron:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"2CC6BD83-D454-4FD8-904D-0A7C083F7AD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:thibault_godouet:fcron:2.9.4:*:*:*:*:*:*:*","matchCriteriaId":"2688EE86-C1A6-466B-B52E-11CFAE118335"}]}]},{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*","matchCriteriaId":"647BA336-5538-4972-9271-383A0EC9378E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2004","CveId":"1033","Ordinal":"1","Title":"CVE-2004-1033","CVE":"CVE-2004-1033","Year":"2004"},"notes":[{"CveYear":"2004","CveId":"1033","Ordinal":"1","NoteData":"Fcron 2.0.1, 2.9.4, and possibly earlier versions leak file descriptors of open files, which allows local users to bypass access restrictions and read fcron.allow and fcron.deny via the EDITOR environment variable.","Type":"Description","Title":"CVE-2004-1033"},{"CveYear":"2004","CveId":"1033","Ordinal":"2","NoteData":"2004-11-24","Type":"Other","Title":"Published"},{"CveYear":"2004","CveId":"1033","Ordinal":"3","NoteData":"2017-07-10","Type":"Other","Title":"Modified"}]}}}