CVE-2004-0733

OllyDbg 1.10 - DoS/RCE

Title source: llm

Description

Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers that are directly provided to the OutputDebugString function call.

Exploits (2)

exploitdb WORKING POC VERIFIED
by jamikazu · textlocalwindows
https://www.exploit-db.com/exploits/3757
exploitdb WORKING POC VERIFIED
by Ahmet Cihan · clocalwindows
https://www.exploit-db.com/exploits/388

Scores

EPSS 0.4426
EPSS Percentile 97.6%

Details

Status published
Products (4)
ollydbg/ollydbg 1.0.6
ollydbg/ollydbg 1.0.8b
ollydbg/ollydbg 1.0.9
ollydbg/ollydbg 1.10
Published Jul 27, 2004
Tracked Since Feb 18, 2026