10

CVE-2004-1034

Buffer overflow in the http_open function in Kaffeine before 0.5, whose code is also used in gxine before 0.3.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long Content-Type header for a Real Audio Media (.ram) playlist file.

Data is provided by the National Vulnerability Database (NVD)
KaffeineKaffeine Player Version0.4.2
KaffeineKaffeine Player Version0.4.3
KaffeineKaffeine Player Version0.4.3b
KaffeineKaffeine Player Version0.5_rc1
XineGxine Version0.3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.93% 0.896
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C