CVE-2004-1095
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Puntuación base: 10
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 9.38%
- Percentil entre todas las CVEs puntuadas: 95
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (3)
CWE
- NVD-CWE-Other
Referencias
- http://marc.info/?l=bugtraq&m=109886210702781&w=2
- http://marc.info/?l=bugtraq&m=109898111915661&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml
- http://www.securityfocus.com/bid/11556
- http://www.svgalib.org/rus/zgv/
- http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17871
- http://marc.info/?l=bugtraq&m=109886210702781&w=2
- http://marc.info/?l=bugtraq&m=109898111915661&w=2
- http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml
- http://www.securityfocus.com/bid/11556
- http://www.svgalib.org/rus/zgv/
- http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17871
JSON original (NVD)
Mostrar
{
"id": "CVE-2004-1095",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2005-01-10T05:00:00.000",
"references": [
{
"url": "http://marc.info/?l=bugtraq&m=109886210702781&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=109898111915661&w=2",
"source": "cve@mitre.org"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/11556",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.svgalib.org/rus/zgv/",
"source": "cve@mitre.org"
},
{
"url": "http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17871",
"source": "cve@mitre.org"
},
{
"url": "http://marc.info/?l=bugtraq&m=109886210702781&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://marc.info/?l=bugtraq&m=109898111915661&w=2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.gentoo.org/security/en/glsa/glsa-200411-12.xml",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/11556",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.svgalib.org/rus/zgv/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.svgalib.org/rus/zgv/zgv-5.8-integer-overflow-fix.diff",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/17871",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct."
},
{
"lang": "es",
"value": "Múltiples desbordamientos de enteros en \r\n\r\nreadbmp.c\r\nreadgif.c\r\nreadgif.c\r\nreadmrf.c\r\nreadpcx.c\r\nreadpng.c\r\nreadpnm.c\r\nreadprf.c\r\nreadtiff.c\r\nreadxbm.c\r\nreadxpm.c\r\n\r\nen zgv 5.8 permite a atacantes remotos ejecutar código de su elección mediante ciertas cabeceras de imágenes que hacen que algunos cálculos se desborden y se asignen pequeños búferes, lo que conduce a desbordamientos. \r\nNota: CAN-2004-0994 y CAN-2004-1095 identifican grupos de errores que solo se solapan parcialmente , a pesar de tener el mismo desarrollador. Por lo tanto, deberían considerarse distintos."
}
],
"lastModified": "2026-06-16T22:07:00.823",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FD1F2C54-7ED1-4157-9330-D9E587308D29"
},
{
"criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C86AC21-33BC-4F2D-BBE6-57A1B53D73E0"
},
{
"criteria": "cpe:2.3:a:zgv:xzgv_image_viewer:0.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "55CEE4AD-7F1E-4BA1-ADD1-2A365D5CE29B"
},
{
"criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A5EB0059-4A50-418E-8FCD-6AC2AAB46A41"
},
{
"criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.6:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "128641DC-20B7-465D-838F-A266E2B1BF24"
},
{
"criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.7:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9BC55295-62B4-468F-B7E2-C1ABEE22C79A"
},
{
"criteria": "cpe:2.3:a:zgv:zgv_image_viewer:5.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "44F5A51B-E3BC-4479-91FE-5F37FD3CEF30"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:alpha:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A6B060E4-B5A6-4469-828E-211C52542547"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:arm:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "974C3541-990C-4CD4-A05A-38FA74A84632"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:hppa:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CBF1E0F-C7F3-4F83-9E60-6E63FA7D2775"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ia-32:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58792F77-B06F-4780-BA25-FE1EE6C3FDD9"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ia-64:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C9419322-572F-4BB6-8416-C5E96541CF33"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:m68k:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BFC50555-C084-46A3-9C9F-949C5E3BB448"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:mips:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C25D6E1-D283-4CEA-B47B-60C47A5C0797"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:mipsel:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD18A446-C634-417E-86AC-B19B6DDDC856"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:ppc:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E4BB852E-61B2-4842-989F-C6C0C901A8D7"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:s-390:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24DD9D59-E2A2-4116-A887-39E8CC2004FC"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:3.0:*:sparc:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F28D7457-607E-4E0C-909A-413F91CFCD82"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}