Vulnerability Intelligence Report
CVE-2004-0888
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:9.33%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| easy_software_products | cups | 1.0.4, 1.0.4_8, 1.1.1, 1.1.4, 1.1.4_2, 1.1.4_3, 1.1.4_5, 1.1.6, 1.1.7, 1.1.10, 1.1.12, 1.1.13, 1.1.14, 1.1.15, 1.1.16, 1.1.17, 1.1.18, 1.1.19, 1.1.19_rc5, 1.1.20 |
| gnome | gpdf | 0.112, 0.131 |
| kde | koffice | 1.3, 1.3.1, 1.3.2, 1.3.3, 1.3_beta1, 1.3_beta2, 1.3_beta3 |
| kde | kpdf | 3.2 |
| pdftohtml | pdftohtml | 0.32a, 0.32b, 0.33, 0.33a, 0.34, 0.35, 0.36 |
| tetex | tetex | 1.0.7, 2.0, 2.0.1, 2.0.2 |
| xpdf | xpdf | 0.90, 0.91, 0.92, 0.93, 1.0, 1.0a, 1.1, 2.0, 2.1, 2.3, 3.0 |
| debian | debian_linux | 3.0 |
| gentoo | linux | all |
| kde | kde | 3.2, 3.2.1, 3.2.2, 3.2.3, 3.3, 3.3.1 |
| redhat | enterprise_linux | 2.1, 3.0 |
| redhat | enterprise_linux_desktop | 3.0 |
| redhat | fedora_core | core_2.0 |
| redhat | linux_advanced_workstation | 2.1 |
| suse | suse_linux | 8.0, 8.1, 8.2, 9.0, 9.1, 9.2 |
| ubuntu | ubuntu_linux | 4.1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
9.334%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2004-09-22T00:00:00 |
| Published | 2004-10-26T04:00:00 |
| Patch Date | 2004-10-21 |
| Last Updated | 2024-08-08T00:31:47 |
Community Chatter & Buzz