Lucene search

K
cve[email protected]CVE-2004-1034
HistoryMar 01, 2005 - 5:00 a.m.

CVE-2004-1034

2005-03-0105:00:00
web.nvd.nist.gov
21
cve-2004-1034
buffer overflow
kaffeine
remote attackers
denial of service
arbitrary code
nvd

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.055 Low

EPSS

Percentile

93.3%

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.

Affected configurations

NVD
Node
kaffeinekaffeine_playerMatch0.4.2
OR
kaffeinekaffeine_playerMatch0.4.3
OR
kaffeinekaffeine_playerMatch0.4.3b
OR
kaffeinekaffeine_playerMatch0.5_rc1
OR
xinegxineMatch0.3
Node
gentoolinux

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.9 High

AI Score

Confidence

High

0.055 Low

EPSS

Percentile

93.3%