7.5

CVE-2005-0064

Exploit

Buffer overflow in the Decrypt::makeFileKey2 function in Decrypt.cc for xpdf 3.00 and earlier allows remote attackers to execute arbitrary code via a PDF file with a large /Encrypt /Length keyLength value.

Data is provided by the National Vulnerability Database (NVD)
XpdfXpdf Version0.2
XpdfXpdf Version0.3
XpdfXpdf Version0.4
XpdfXpdf Version0.5
XpdfXpdf Version0.5a
XpdfXpdf Version0.6
XpdfXpdf Version0.7
XpdfXpdf Version0.7a
XpdfXpdf Version0.80
XpdfXpdf Version0.90
XpdfXpdf Version0.91
XpdfXpdf Version0.91a
XpdfXpdf Version0.91b
XpdfXpdf Version0.91c
XpdfXpdf Version0.92
XpdfXpdf Version0.92a
XpdfXpdf Version0.92b
XpdfXpdf Version0.92c
XpdfXpdf Version0.92d
XpdfXpdf Version0.92e
XpdfXpdf Version0.93
XpdfXpdf Version0.93a
XpdfXpdf Version0.93b
XpdfXpdf Version0.93c
XpdfXpdf Version1.0
XpdfXpdf Version1.0a
XpdfXpdf Version1.1
XpdfXpdf Version2.0
XpdfXpdf Version2.1
XpdfXpdf Version2.2
XpdfXpdf Version2.3
XpdfXpdf Version3.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 8.4% 0.919
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P