Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2006-2480

Опубликовано: 19 мая 2006
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS2: 5.1

Описание

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

РелизСтатусПримечание
dapper

released

0.94.0-17.1ubuntu3
devel

released

0.94.0-17.1ubuntu3
edgy

released

0.94.0-17.1ubuntu3
feisty

released

0.94.0-17.1ubuntu3
upstream

needs-triage

Показывать по

EPSS

Процентиль: 96%
0.25823
Средний

5.1 Medium

CVSS2

Связанные уязвимости

redhat
больше 21 года назад

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

nvd
больше 19 лет назад

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

debian
больше 19 лет назад

Format string vulnerability in Dia 0.94 allows user-assisted attackers ...

github
больше 3 лет назад

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

EPSS

Процентиль: 96%
0.25823
Средний

5.1 Medium

CVSS2