Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-0994

EPSS 17.53% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-0994

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
xzgv 多个 整数溢出漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
xzgv是一款开源的X界面下的图片浏览器软件。 Xzgv 0.8版本中存在多个整数溢出漏洞。 远程攻击者可通过包含超大的width/height值图片文件,触发溢出。如read_prf_file功能模块中readprf.c就可以被攻击者利用,从而可能执行任意代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-0994

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0994

登录查看更多情报信息。

Same Patch Batch · n/a · 2004-12-15 · 61 CVEs total

CVE-2004-1214russobit-m kreed nickname/message 缓冲区溢出漏洞
CVE-2004-1232Gadu-Gadu ImagesFilename 堆栈溢出漏洞
CVE-2004-1229Gadu-Gadu parse 跨站脚本攻击漏洞
CVE-2004-1228SugarCRM SugarSales 信息泄露漏洞
CVE-2004-1227SugarCRM SugarSales 多处 目录遍历漏洞
CVE-2004-1230Gadu-Gadu 信息泄露漏洞
CVE-2004-1218ibexsoftware RemoteExecute 远程拒绝服务漏洞
CVE-2004-1217HostingController 多个 信息泄露漏洞
CVE-2004-1216russobit-m kreed nickname/modeltype 拒绝服务漏洞
CVE-2004-1215russobit-m kreed UDP 拒绝服务漏洞
CVE-2004-1219PHPArena paFileDB session 信息泄露漏洞
CVE-2004-1213AdvancedGuestbook index.php 跨站脚本攻击漏洞
CVE-2004-1212BlogTorrent btdownload.php 目录遍历漏洞
CVE-2004-1211PegasusMail Mercury/32 IMAP 缓冲区溢出漏洞
CVE-2004-1210IPCop proxylog.dat 跨站脚本攻击漏洞
CVE-2004-1209Verisign PayflowLink 数据篡改漏洞
CVE-2004-120821-6.com Orbz 缓冲区溢出漏洞
CVE-2004-1207Serious 多个软件 拒绝服务漏洞
CVE-2004-1206canvas.anubix.net PnTresMailer codebrowserpntm.php 目录遍历漏洞
CVE-2004-1205canvas.anubix.net PnTresMailer codebrowserpntm.php 信息泄露漏洞

Showing top 20 of 61 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-0994

No comments yet


Leave a comment