Lucene search

K
nvd[email protected]NVD:CVE-2004-0914
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-0914

2005-01-1005:00:00
web.nvd.nist.gov

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.088 Low

EPSS

Percentile

94.6%

Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (application crash), or execute arbitrary code via a certain XPM image file. NOTE: it is highly likely that this candidate will be SPLIT into other candidates in the future, per CVE’s content decisions.

Affected configurations

NVD
Node
lesstiflesstifMatch0.93
OR
lesstiflesstifMatch0.93.12
OR
lesstiflesstifMatch0.93.18
OR
lesstiflesstifMatch0.93.34
OR
lesstiflesstifMatch0.93.36
OR
lesstiflesstifMatch0.93.40
OR
lesstiflesstifMatch0.93.91
OR
lesstiflesstifMatch0.93.94
OR
lesstiflesstifMatch0.93.96
OR
x.orgx11r6Match6.7.0
OR
x.orgx11r6Match6.8
OR
x.orgx11r6Match6.8.1
OR
xfree86_projectx11r6Match3.3
OR
xfree86_projectx11r6Match3.3.2
OR
xfree86_projectx11r6Match3.3.3
OR
xfree86_projectx11r6Match3.3.4
OR
xfree86_projectx11r6Match3.3.5
OR
xfree86_projectx11r6Match3.3.6
OR
xfree86_projectx11r6Match4.0
OR
xfree86_projectx11r6Match4.0.1
OR
xfree86_projectx11r6Match4.0.2.11
OR
xfree86_projectx11r6Match4.0.3
OR
xfree86_projectx11r6Match4.1.0
OR
xfree86_projectx11r6Match4.1.11
OR
xfree86_projectx11r6Match4.1.12
OR
xfree86_projectx11r6Match4.2.0
OR
xfree86_projectx11r6Match4.2.1
OR
xfree86_projectx11r6Match4.2.1errata
OR
xfree86_projectx11r6Match4.3.0
Node
gentoolinux
OR
redhatfedora_coreMatchcore_2.0
OR
redhatfedora_coreMatchcore_3.0
OR
susesuse_linuxMatch1.0desktop
OR
susesuse_linuxMatch8enterprise_server
OR
susesuse_linuxMatch8.1
OR
susesuse_linuxMatch8.2
OR
susesuse_linuxMatch9.0
OR
susesuse_linuxMatch9.0enterprise_server
OR
susesuse_linuxMatch9.1
OR
susesuse_linuxMatch9.2

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.7 High

AI Score

Confidence

High

0.088 Low

EPSS

Percentile

94.6%