10
CVSSv2

CVE-2004-0994

Published: 10/01/2005 Updated: 11/07/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple integer overflows in xzgv 0.8 and previous versions allow remote malicious users to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.

Vulnerable Product Search on Vulmon Subscribe to Product

zgv zgv image viewer 5.8

zgv zgv image viewer 5.6

zgv zgv image viewer 5.7

zgv xzgv image viewer 0.8

zgv zgv image viewer 5.5

zgv xzgv image viewer 0.6

zgv xzgv image viewer 0.7

debian debian linux 3.0

Vendor Advisories

Luke "infamous41md" discovered multiple vulnerabilities in xzgv, a picture viewer for X11 with a thumbnail-based selector Remote exploitation of an integer overflow vulnerability could allow the execution of arbitrary code For the stable distribution (woody) these problems have been fixed in version 07-6woody2 For the unstable distribution (sid ...