7.5

CVE-2004-0687

Multiple stack-based buffer overflows in (1) xpmParseColors in parse.c, (2) ParseAndPutPixels in create.c, and (3) ParsePixels in parse.c for libXpm before 6.8.1 allow remote attackers to execute arbitrary code via a malformed XPM image file.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
X.OrgX11r6 Version6.7.0
X.OrgX11r6 Version6.8
Xfree86 ProjectX11r6 Version3.3.6
Xfree86 ProjectX11r6 Version4.0
Xfree86 ProjectX11r6 Version4.0.1
Xfree86 ProjectX11r6 Version4.0.2.11
Xfree86 ProjectX11r6 Version4.0.3
Xfree86 ProjectX11r6 Version4.1.0
Xfree86 ProjectX11r6 Version4.1.11
Xfree86 ProjectX11r6 Version4.1.12
Xfree86 ProjectX11r6 Version4.2.0
Xfree86 ProjectX11r6 Version4.2.1
Xfree86 ProjectX11r6 Version4.2.1 Editionerrata
Xfree86 ProjectX11r6 Version4.3.0
OpenbsdOpenbsd Version3.4
OpenbsdOpenbsd Version3.5
SuseSuse Linux Version8 Editionenterprise_server
SuseSuse Linux Version8.1
SuseSuse Linux Version8.2
SuseSuse Linux Version9.0
SuseSuse Linux Version9.0 Editionenterprise_server
SuseSuse Linux Version9.0 Editionx86_64
SuseSuse Linux Version9.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.95% 0.949
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P