{"cve":{"cve_id":"CVE-2004-0597","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.82537,"epss_percentile":0.99621,"epss_as_of":"2026-06-23","description":"Multiple buffer overflows in libpng 1.2.5 and earlier, as used in multiple products, allow remote attackers to execute arbitrary code via malformed PNG images in which (1) the png_handle_tRNS function does not properly validate the length of transparency chunk (tRNS) data, or the (2) png_handle_sBIT or (3) png_handle_hIST functions do not perform sufficient bounds checking.","published_at":"2004-08-05T04:00:00Z","last_modified_at":"2026-06-16T22:05:57.273000Z","cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":null,"ssvc_automatable":null,"ssvc_technical_impact":null,"cwes":null,"nvd_references":["http://www.trustix.net/errata/2004/0040/","http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2274","http://www.mozilla.org/projects/security/known-vulnerabilities.html","ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt","http://www.redhat.com/support/errata/RHSA-2004-421.html","http://www.redhat.com/support/errata/RHSA-2004-402.html","http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml","http://secunia.com/advisories/22958","http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1","http://marc.info/?l=bugtraq&m=109900315219363&w=2","https://bugzilla.fedora.us/show_bug.cgi?id=1943","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A594","http://www.us-cert.gov/cas/techalerts/TA05-039A.html","https://exchange.xforce.ibmcloud.com/vulnerabilities/16894","http://marc.info/?l=bugtraq&m=109761239318458&w=2","http://scary.beasts.org/security/CESA-2004-001.txt","http://www.redhat.com/support/errata/RHSA-2004-429.html","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2378","http://www.securityfocus.com/bid/15495","http://www.debian.org/security/2004/dsa-536","http://www.kb.cert.org/vuls/id/388984","http://lists.apple.com/mhonarc/security-announce/msg00056.html","http://www.kb.cert.org/vuls/id/817368","http://marc.info/?l=bugtraq&m=109163866717909&w=2","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4492","http://marc.info/?l=bugtraq&m=109181639602978&w=2","https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-009","http://www.mandriva.com/security/advisories?name=MDKSA-2006:213","http://www.us-cert.gov/cas/techalerts/TA04-217A.html","http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7709","http://www.mandriva.com/security/advisories?name=MDKSA-2006:212","http://marc.info/?l=bugtraq&m=110796779903455&w=2","http://www.coresecurity.com/common/showdoc.php?idx=421&idxseccion=10","http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856","http://www.securityfocus.com/bid/10857","http://www.novell.com/linux/security/advisories/2004_23_libpng.html","http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml","https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11284","http://www.mandriva.com/security/advisories?name=MDKSA-2004:079","http://secunia.com/advisories/22957"],"vuln_status":"Modified","trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-28T23:02:41.074100Z"},"effective_severity":null,"badges":["epss"],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"greg-roelofs","vendor_name":"greg_roelofs","product_slug":"libpng","product_name":"libpng","version_start":null,"version_start_inclusive":null,"version_end":"1.2.5","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:greg_roelofs:libpng:*:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"msn-messenger","product_name":"msn_messenger","version_start":"6.1","version_start_inclusive":true,"version_end":"6.1","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:msn_messenger:6.1:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"msn-messenger","product_name":"msn_messenger","version_start":"6.2","version_start_inclusive":true,"version_end":"6.2","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:msn_messenger:6.2:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-98se","product_name":"windows_98se","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_98se:*:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-me","product_name":"windows_me","version_start":null,"version_start_inclusive":null,"version_end":null,"version_end_inclusive":null,"cpe23_uri":"cpe:2.3:o:microsoft:windows_me:*:*:second_edition:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-media-player","product_name":"windows_media_player","version_start":"9","version_start_inclusive":true,"version_end":"9","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:windows_media_player:9:*:*:*:*:*:*:*"},{"vendor_slug":"microsoft","vendor_name":"Microsoft","product_slug":"windows-messenger","product_name":"windows_messenger","version_start":"5.0","version_start_inclusive":true,"version_end":"5.0","version_end_inclusive":true,"cpe23_uri":"cpe:2.3:a:microsoft:windows_messenger:5.0:*:*:*:*:*:*:*"}],"exploit_refs":[],"news":[],"references":[{"url":"http://www.trustix.net/errata/2004/0040/","source_type":"MISC","tags":[]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=1-66-200663-1","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2274","source_type":"MISC","tags":[]},{"url":"http://www.mozilla.org/projects/security/known-vulnerabilities.html","source_type":"MISC","tags":[]},{"url":"ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.49/SCOSA-2005.49.txt","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2004-421.html","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2004-402.html","source_type":"MISC","tags":[]},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200408-22.xml","source_type":"MISC","tags":[]},{"url":"http://secunia.com/advisories/22958","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://sunsolve.sun.com/search/document.do?assetkey=urn:cds:docid:1-21-114816-02-1","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=109900315219363&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://bugzilla.fedora.us/show_bug.cgi?id=1943","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A594","source_type":"MISC","tags":[]},{"url":"http://www.us-cert.gov/cas/techalerts/TA05-039A.html","source_type":"MISC","tags":[]},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/16894","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=109761239318458&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://scary.beasts.org/security/CESA-2004-001.txt","source_type":"MISC","tags":[]},{"url":"http://www.redhat.com/support/errata/RHSA-2004-429.html","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2378","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/bid/15495","source_type":"MISC","tags":[]},{"url":"http://www.debian.org/security/2004/dsa-536","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.kb.cert.org/vuls/id/388984","source_type":"MISC","tags":[]},{"url":"http://lists.apple.com/mhonarc/security-announce/msg00056.html","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.kb.cert.org/vuls/id/817368","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=109163866717909&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4492","source_type":"MISC","tags":[]},{"url":"http://marc.info/?l=bugtraq&m=109181639602978&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-009","source_type":"MISC","tags":[]},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:213","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.us-cert.gov/cas/techalerts/TA04-217A.html","source_type":"MISC","tags":[]},{"url":"http://www.adobe.com/support/downloads/detail.jsp?ftpID=2679","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7709","source_type":"MISC","tags":[]},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2006:212","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://marc.info/?l=bugtraq&m=110796779903455&w=2","source_type":"MAILING_LIST","tags":["mailing-list"]},{"url":"http://www.coresecurity.com/common/showdoc.php?idx=421&idxseccion=10","source_type":"MISC","tags":[]},{"url":"http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000856","source_type":"MISC","tags":[]},{"url":"http://www.securityfocus.com/bid/10857","source_type":"MISC","tags":[]},{"url":"http://www.novell.com/linux/security/advisories/2004_23_libpng.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://www.gentoo.org/security/en/glsa/glsa-200408-03.xml","source_type":"MISC","tags":[]},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11284","source_type":"MISC","tags":[]},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2004:079","source_type":"VENDOR_ADVISORY","tags":["advisory"]},{"url":"http://secunia.com/advisories/22957","source_type":"VENDOR_ADVISORY","tags":["advisory"]}],"timeline":[{"type":"published","at":"2004-08-05T04:00:00Z","label":"CVE published","source":null}]}