Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2004-2372

Опубликовано: 31 дек. 2004
Источник: nvd
CVSS2: 7.2
EPSS Низкий

Описание

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:bochs_project:bochs:*:*:*:*:*:*:*:*
Версия до 2.1.1 (исключая)

EPSS

Процентиль: 32%
0.00123
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

debian
почти 21 год назад

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows loc ...

github
больше 3 лет назад

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.

EPSS

Процентиль: 32%
0.00123
Низкий

7.2 High

CVSS2

Дефекты

NVD-CWE-Other