Vulnerability Database

289,599

Total vulnerabilities in the database

CVE-2004-0989

Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL containing FTP data that is not properly handled by the xmlNanoFTPScanProxy function, and other overflows related to manipulation of DNS length values, including (3) xmlNanoFTPConnect, (4) xmlNanoHTTPConnectHost, and (5) xmlNanoHTTPConnectHost.

  • Published: Mar 1, 2005
  • Updated: Apr 13, 2023
  • CVE: CVE-2004-0989
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 10
  • AV:N/AC:L/Au:N/C:C/I:C/A:C

No CWE or OWASP classifications available.

Software From Fixed in
xmlsoft / libxml2 2.6.11 2.6.11.x
xmlsoft / libxml2 2.6.13 2.6.13.x
xmlsoft / libxml2 2.6.7 2.6.7.x
xmlsoft / libxml2 2.6.14 2.6.14.x
xmlstarlet / command_line_xml_toolkit 0.9.1 0.9.1.x
xmlsoft / libxml2 2.6.8 2.6.8.x
xmlsoft / libxml2 2.5.11 2.5.11.x
xmlsoft / libxml 1.8.17 1.8.17.x
xmlsoft / libxml2 2.6.12 2.6.12.x
xmlsoft / libxml2 2.6.9 2.6.9.x
xmlsoft / libxml2 2.6.6 2.6.6.x
redhat / fedora_core core_2.0 core_2.0.x
trustix / secure_linux 2.0 2.0.x
ubuntu / ubuntu_linux 4.1 4.1.x
trustix / secure_linux 2.1 2.1.x