« Volver al listado

CVE-2004-0994

Estado: ModificadaAlta (10)—

Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-0994",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2005-01-10T05:00:00.000",
  "references": [
    {
      "url": "http://marc.info/?l=bugtraq&m=110297198402077&w=2",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.debian.org/security/2004/dsa-614",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18454",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://marc.info/?l=bugtraq&m=110297198402077&w=2",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.debian.org/security/2004/dsa-614",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18454",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct."
    },
    {
      "lang": "es",
      "value": "Múltiples desbordamientos de enteros en xzgv 0.8 y anteriores permiten a atacantes remotos ejecutar código de su elección mediante imágenes con valores de anchura y altura largos, lo que dispara un desbordamiento de búfer basado en el montón, como se ha demostrado en la función read_prf_file de readprf.c.\r\nNota: CAN-2004-0994 y CAN-2004-1095 identifican grupos de errores que se solapan sólo parcialemte, a pesar de tener el mismo desarrollador. Por lo tanto, deberían considerarse como diferentes."
    }
  ],
  "lastModified": "2026-06-16T22:06:48.910",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FD1F2C54-7ED1-4157-9330-D9E587308D29"
            },
            {
              "criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C86AC21-33BC-4F2D-BBE6-57A1B53D73E0"
            },
            {
              "criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55CEE4AD-7F1E-4BA1-ADD1-2A365D5CE29B"
            },
            {
              "criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A5EB0059-4A50-418E-8FCD-6AC2AAB46A41"
            },
            {
              "criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "128641DC-20B7-465D-838F-A266E2B1BF24"
            },
            {
              "criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9BC55295-62B4-468F-B7E2-C1ABEE22C79A"
            },
            {
              "criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44F5A51B-E3BC-4479-91FE-5F37FD3CEF30"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6B060E4-B5A6-4469-828E-211C52542547"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "974C3541-990C-4CD4-A05A-38FA74A84632"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6CBF1E0F-C7F3-4F83-9E60-6E63FA7D2775"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "58792F77-B06F-4780-BA25-FE1EE6C3FDD9"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9419322-572F-4BB6-8416-C5E96541CF33"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFC50555-C084-46A3-9C9F-949C5E3BB448"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9C25D6E1-D283-4CEA-B47B-60C47A5C0797"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD18A446-C634-417E-86AC-B19B6DDDC856"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E4BB852E-61B2-4842-989F-C6C0C901A8D7"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "24DD9D59-E2A2-4116-A887-39E8CC2004FC"
            },
            {
              "criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F28D7457-607E-4E0C-909A-413F91CFCD82"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}