CyberSec.Space Logo
Back to CVE Browser

CVE-2004-0989

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1720%
EPSS Percentile42.28th
PublishedMar 1, 2005
Last ModifiedApr 16, 2026

Vulnerability Description

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

Affected Platforms (CPE)

πŸ“¦
Xmlsoft

Libxml

= 1.8.17
πŸ“¦
Xmlsoft

Libxml2

= 2.5.11
πŸ“¦
Xmlsoft

Libxml2

= 2.6.6
πŸ“¦
Xmlsoft

Libxml2

= 2.6.7
πŸ“¦
Xmlsoft

Libxml2

= 2.6.8
πŸ“¦
Xmlsoft

Libxml2

= 2.6.9
πŸ“¦
Xmlsoft

Libxml2

= 2.6.11
πŸ“¦
Xmlsoft

Libxml2

= 2.6.12
πŸ“¦
Xmlsoft

Libxml2

= 2.6.13
πŸ“¦
Xmlsoft

Libxml2

= 2.6.14
πŸ“¦
Xmlstarlet

Command Line Xml Toolkit

= 0.9.1
πŸ’»
Redhat

Fedora Core

= core_2.0
πŸ’»
Trustix

Secure Linux

= 2.0
πŸ’»
Trustix

Secure Linux

= 2.1
πŸ’»
Ubuntu

Ubuntu Linux

= 4.1
πŸ’»
Ubuntu

Ubuntu Linux

= 4.1

References & Advisories

Related Vulnerabilities