CVE-2004-1095
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c i...
Affects 3 products across 2 vendors.
Multiple integer overflows in various image reading functions in zgv 5.8 can lead to buffer overflows, allowing remote attackers to execute arbitrary code.
BSID: BS-2005-GLOBAL-159327-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2004-1095?
What is the CVSS score for CVE-2004-1095?
Is CVE-2004-1095 actively exploited?
How do I remediate CVE-2004-1095?
What systems are affected by CVE-2004-1095?
| CVE ID | CVE-2004-1095 |
|---|---|
| BSID | BS-2005-GLOBAL-159327-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2005-01-10 |
| Last Modified | 2026-04-16 |
| ICS Relevance | 0% |
| Source | NVD |
Multiple integer overflows in (1) readbmp.c, (2) readgif.c, (3) readgif.c, (4) readmrf.c, (5) readpcx.c, (6) readpng.c,(7) readpnm.c, (8) readprf.c, (9) readtiff.c, (10) readxbm.c, (11) readxpm.c in zgv 5.8 allow remote attackers to execute arbitrary code via certain image headers that cause calculations to be overflowed and small buffers to be allocated, leading to buffer overflows. NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer. Therefore, they should be regarded as distinct.
Source: NIST NVD / MITRE CVE Database
Attackers can exploit these vulnerabilities by crafting malicious image files with specific headers that cause integer overflows during the image processing. This results in small buffers being allocated, leading to buffer overflows and potential code execution.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Debian | Debian Linux | — |
| Zgv | Zgv Image Viewer | — |
| Zgv | Xzgv Image Viewer | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →