CVE-2004-0964

CRITICAL ⚠ Exploit

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

Affects 2 products across 2 vendors.

BCS8.99
CVSS 2.010.0
EPSS62.7%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A buffer overflow vulnerability in Zinf 2.2.1 on Windows and other older versions for Linux allows attackers to execute arbitrary code through specially crafted .pls files.

BSID: BS-2005-GLOBAL-171275-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-0964?
A buffer overflow vulnerability in Zinf 2.2.1 on Windows and other older versions for Linux allows attackers to execute arbitrary code through specially crafted .pls files.
What is the CVSS score for CVE-2004-0964?
CVE-2004-0964 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 62.7%.
Is CVE-2004-0964 actively exploited?
Public exploit available for CVE-2004-0964. Exploitation risk elevated.
How do I remediate CVE-2004-0964?
Priority: IMMEDIATE. Advisory: http://www.debian.org/security/2004/dsa-587 PSIRT: [email protected]
What systems are affected by CVE-2004-0964?
CVE-2004-0964 affects: Debian, Zinf.
Vulnerability Details
CVE IDCVE-2004-0964
BSIDBS-2005-GLOBAL-171275-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-02-09
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by a buffer overflow when Zinf processes a .pls file with certain values, which can lead to arbitrary code execution with the privileges of the user running Zinf.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Debian Debian Linux
Zinf Zinf
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 7823 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Debian
CVE-2000-0666 10.0 rpc.statd in the nfs-utils package in various Linux distributions does not pr... CVE-2001-0233 10.0 Buffer overflow in micq client 0.4.6 and earlier allows remote attackers to c... CVE-2005-3625 10.0 Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS... CVE-2001-0554 10.0 Buffer overflow in BSD-based telnetd telnet daemon on various operating syste... CVE-2003-0648 10.0 Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local use...
View all Debian CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →