Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-0990

EPSS 21.21% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-0990

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
GD 'gd_png.c' 整数溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
GD是动态建立图象的图形库实现。 GD在处理装载PNG图象文件时分配内存函数存在整数溢出,远程攻击者可以利用这个漏洞可能以进程权限执行任意指令。 问题存在gd_png.c文件的gdImageCreateFromPngCtx()函数中,此函数由gdImageCreateFromPng()调用,函数用于装载图象文件到GD数据结构,问题是当对图象分配内存时,由于对输入参数缺少充分检查,可导致整数溢出,精心构建PNG图象,诱使用户访问,可能以进程权限执行任意指令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-0990

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0990

Please Login to view more intelligence information

Same Patch Batch · n/a · 2004-10-28 · 14 CVEs total

CVE-2004-0510OpenServer MMDF多个缓冲区溢出漏洞
CVE-2004-0511OpenServer MMDF多个缓冲区溢出漏洞
CVE-2004-0512OpenServer MMDF多个缓冲区溢出漏洞
CVE-2004-0814Linux Kernel TIOCSETD终端子系统竞态条件漏洞
CVE-2004-0921Apple MacOS AFP 拒绝服务漏洞
CVE-2004-0922Apple MacOS X AFP 文件权限设置漏洞
CVE-2004-0924Apple MacOS X NetInfoManager 账户信息误报漏洞
CVE-2004-0925Apple MacOS X postfix 拒绝服务漏洞
CVE-2004-0926Apple MacOS QuickTime 缓冲区溢出漏洞
CVE-2004-0927Apple MacOS ServerAdmin 默认证书漏洞
CVE-2004-0962Apple远程桌面客户端本地权限提升漏洞
CVE-2004-0988Apple QuickTime 远程任意代码执行漏洞
CVE-2004-0989libxml2 缓冲区溢出漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2004-0990

No comments yet


Leave a comment