7.5

CVE-2004-2304

Integer overflow in Trillian 0.74 and earlier, and Trillian Pro 2.01 and earlier, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a directIM packet that triggers a heap-based buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
Cerulean StudiosTrillian Version0.71
Cerulean StudiosTrillian Version0.73
Cerulean StudiosTrillian Version0.74
Cerulean StudiosTrillian Version0.725
Cerulean StudiosTrillian Pro Version2.01
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 3.24% 0.859
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P