VDB

CVE-2004-0990

CVE-2004-0990 PUBLISHED CVSS 10 CRITICAL

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

EPSS 28.26% · 97.9th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
28.26%
97.9th percentile

Affected Products

VendorProductVersions
gentoolinux
trustixsecure_linux2.2, 2.1, 1.5
gd_graphics_librarygdlib2.0.20, 2.0.23, 2.0.26
n/an/an/a
openpkgopenpkg2.2, *, 2.1
susesuse_linux8.1, 8.2, 9.0

Timeline

  • CVE Published
  • Sep 23, 2010 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 27, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • Jul 17, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›