CVE-2004-0806
7.2
CVSS v2.0 Base Score
1.73%
LOW RiskEPSS (75th percentile)
NVD-CWE-Other
cdrecord in the cdrtools package before 2.01, when installed setuid root, does not properly drop privileges before executing a program specified in the RSH environment variable, which allows local users to gain privileges.
Published: 12/31/2004
Modified: 6/16/2026
Vulnerability Summary
CVSS v2 Score
7.2
AV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS Score (Exploitation Probability)
1.73%LOW Exploitation Risk
75th percentile
This vulnerability has a 1.73% probability of being exploited in the next 30 days, ranking higher than 75% of all scored CVEs.
CWE Classification
NVD-CWE-Other