Lucene search

K
cve[email protected]CVE-2004-2541
HistoryNov 20, 2005 - 9:00 p.m.

CVE-2004-2541

2005-11-2021:00:00
CWE-119
web.nvd.nist.gov
34
cscope
buffer overflow
remote code execution
security vulnerability

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.053 Low

EPSS

Percentile

93.1%

Buffer overflow in Cscope 15.5, and possibly multiple overflows, allows remote attackers to execute arbitrary code via a C file with a long #include line that is later browsed by the target.

Affected configurations

NVD
Node
cscopecscopeMatch15.5
CPENameOperatorVersion
cscope:cscopecscopeeq15.5

6.9 Medium

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.053 Low

EPSS

Percentile

93.1%