CVE-2004-0989

10.0
CVSS v2.0 Base Score
21.69%
LOW RiskEPSS (98th percentile)
NVD-CWE-Other

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

Published: 3/1/2005
Modified: 6/16/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v2 Score

10

AV:N/AC:L/Au:N/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

21.69%LOW Exploitation Risk
98th percentile

This vulnerability has a 21.69% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.

CWE Classification

NVD-CWE-Other
Advertisement