Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-0597

Опубликовано: 23 нояб. 2004
Источник: nvd
CVSS2: 10
EPSS Высокий

Описание

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:greg_roelofs:libpng:*:*:*:*:*:*:*:*
Версия до 1.2.5 (включая)
cpe:2.3:a:microsoft:msn_messenger:6.1:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:msn_messenger:6.2:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*
cpe:2.3:a:microsoft:windows_messenger:5.0:*:*:*:*:*:*:*
Конфигурация 2

Одно из

cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows_me:*:*:second_edition:*:*:*:*:*

EPSS

Процентиль: 99%
0.84316
Высокий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
больше 20 лет назад

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

redhat
около 21 года назад

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

debian
больше 20 лет назад

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in mult ...

github
больше 3 лет назад

Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.

fstec
больше 20 лет назад

Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 99%
0.84316
Высокий

10 Critical

CVSS2

Дефекты

NVD-CWE-Other