{
  "modified": "2025-09-20T17:02:05Z",
  "published": "2005-01-10T05:00:00Z",
  "id": "CVE-2004-0994",
  "details": "Multiple integer overflows in xzgv 0.8 and earlier allow remote attackers to execute arbitrary code via images with large width and height values, which trigger a heap-based buffer overflow, as demonstrated in the read_prf_file function in readprf.c.  NOTE: CVE-2004-0994 and CVE-2004-1095 identify sets of bugs that only partially overlap, despite having the same developer.  Therefore, they should be regarded as distinct.",
  "references": [
    {
      "type": "ADVISORY",
      "url": "http://www.debian.org/security/2004/dsa-614"
    },
    {
      "type": "WEB",
      "url": "http://marc.info/?l=bugtraq\u0026m=110297198402077\u0026w=2"
    },
    {
      "type": "WEB",
      "url": "http://rus.members.beeb.net/xzgv-0.8-integer-overflow-fix.diff"
    },
    {
      "type": "WEB",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/18454"
    }
  ]
}
