10
CVE-2004-0597
- EPSS 85.09%
- Veröffentlicht 23.11.2004 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Greg Roelofs ≫ Libpng Version <= 1.2.5
Microsoft ≫ Msn Messenger Version6.1
Microsoft ≫ Msn Messenger Version6.2
Microsoft ≫ Windows Media Player Version9
Microsoft ≫ Windows Messenger Version5.0
Microsoft ≫ Windows Me Editionsecond_edition
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 85.09% | 0.993 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|