CVE-2004-0964

CRITICAL ⚠ Exploit

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

Affects 2 products across 2 vendors.

BCS8.99
CVSS 2.010.0
EPSS62.7%
Percentile99th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A buffer overflow vulnerability in Zinf 2.2.1 on Windows and other older versions for Linux allows attackers to execute arbitrary code through specially crafted .pls files.

BSID: BS-2005-GLOBAL-171275-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-0964?
A buffer overflow vulnerability in Zinf 2.2.1 on Windows and other older versions for Linux allows attackers to execute arbitrary code through specially crafted .pls files.
What is the CVSS score for CVE-2004-0964?
CVE-2004-0964 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 62.7%.
Is CVE-2004-0964 actively exploited?
Public exploit available for CVE-2004-0964. Exploitation risk elevated.
How do I remediate CVE-2004-0964?
Priority: IMMEDIATE. Advisory: http://www.debian.org/security/2004/dsa-587 PSIRT: [email protected]
What systems are affected by CVE-2004-0964?
CVE-2004-0964 affects: Debian, Zinf.
Vulnerability Details
CVE IDCVE-2004-0964
BSIDBS-2005-GLOBAL-171275-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-02-09
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to execute arbitrary code via certain values in a .pls file.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is triggered by a buffer overflow when Zinf processes a .pls file with certain values, which can lead to arbitrary code execution with the privileges of the user running Zinf.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Debian Debian Linux
Zinf Zinf
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 7847 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Debian
CVE-2000-0666 10.0 rpc.statd in the nfs-utils package in various Linux distributions does not pr... CVE-2000-0844 10.0 Some functions that implement the locale subsystem on Unix do not properly c... CVE-2008-1673 10.0 The asn1 implementation in (a) the Linux kernel 2.4 before 2.4.36.6 and 2.6 b... CVE-2008-3529 10.0 Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.... CVE-1999-0046 10.0 Buffer overflow of rlogin program using TERM environmental variable.
View all Debian CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →