← Vulnerability feed

Vulnerability record · CVE-2004-0783 · published 20 October 2004

CVE-2004-0783: Gnome gdkpixbuf out-of-bounds write vulnerability

Gnome · Gdkpixbuf

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

7.5 CVSS 2.0 High EPSS 9.4% · top 4.7% CWE-787 · Out-of-bounds write
7.5CVSS 2.0 base score
9.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in xpm_extract_color (io-xpm.c) in the XPM image decoder for gtk+ 2.4.4 (gtk2) and earlier, and gdk-pixbuf before 0.22, may allow remote attackers to execute arbitrary code via a certain color string. NOTE: this identifier is ONLY for gtk+. It was incorrectly referenced in an advisory for a different issue (CVE-2004-0688).

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000875 Third Party Advisory
http://marc.info/?l=bugtraq&m=109528994916275&w=2 Third Party Advisory
http://scary.beasts.org/security/CESA-2004-005.txt Third Party Advisory
http://secunia.com/advisories/17657 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1 Third Party Advisory
http://www.kb.cert.org/vuls/id/369358 Third Party AdvisoryUS Government Resource
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095 Third Party Advisory
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214 Broken Link
http://www.redhat.com/support/errata/RHSA-2004-447.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-466.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/419771/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/11195 Third Party AdvisoryVDB Entry
https://bugzilla.fedora.us/show_bug.cgi?id=2005 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/17385 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1786 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9348 Broken Link
http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000875 Third Party Advisory
http://marc.info/?l=bugtraq&m=109528994916275&w=2 Third Party Advisory
http://scary.beasts.org/security/CESA-2004-005.txt Third Party Advisory
http://secunia.com/advisories/17657 Broken Link
http://sunsolve.sun.com/search/document.do?assetkey=1-26-101776-1 Third Party Advisory
http://www.kb.cert.org/vuls/id/369358 Third Party AdvisoryUS Government Resource
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:095 Third Party Advisory
http://www.mandrakesecure.net/en/advisories/advisory.php?name=MDKSA-2004:096 Third Party Advisory
http://www.mandriva.com/security/advisories?name=MDKSA-2005:214 Broken Link
http://www.redhat.com/support/errata/RHSA-2004-447.html PatchVendor Advisory
http://www.redhat.com/support/errata/RHSA-2004-466.html PatchVendor Advisory
http://www.securityfocus.com/archive/1/419771/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/11195 Third Party AdvisoryVDB Entry
https://bugzilla.fedora.us/show_bug.cgi?id=2005 Issue Tracking
https://exchange.xforce.ibmcloud.com/vulnerabilities/17385 Third Party AdvisoryVDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1786 Broken Link
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9348 Broken Link

Track CVE-2004-0783 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-0828Gnome gtk out-of-bounds write vulnerabilityHeap-based buffer overflow in Xchat-WDK before 1499-4 (2012-01-18) xchat 2.8.6 on Maemo architecture could allow remote attackers to cause a denial o…EPSS 4.3%9.3CVE-2010-4833Gnome gtk untrusted search path vulnerabilityUntrusted search path vulnerability in modules/engines/ms-windows/xp_theme.c in GTK+ before 2.24.0 allows local users to gain privileges via a Trojan…EPSS 2.0%8.8CVE-2021-44648Gnome gdkpixbuf out-of-bounds write vulnerabilityGNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with…EPSS 1.9%7.8CVE-2022-48622Gnome gdkpixbuf out-of-bounds write vulnerabilityIn GNOME GdkPixbuf (aka gdk-pixbuf) through 2.42.10, the ANI (Windows animated cursor) decoder encounters heap memory corruption (in ani_load_chunk i…EPSS 0.42%7.8CVE-2005-2975Gnome gdkpixbuf vulnerabilityio-xpm.c in the gdk-pixbuf XPM image rendering library in GTK+ before 2.8.7 allows attackers to cause a denial of service (infinite loop) via a craft…EPSS 3.7%7.5CVE-2005-2976Gnome gdkpixbuf integer overflow vulnerabilityInteger overflow in io-xpm.c in gdk-pixbuf 0.22.0 in GTK+ before 2.8.7 allows attackers to cause a denial of service (crash) or execute arbitrary cod…EPSS 4.5%7.5CVE-2005-3186Gnome gdkpixbuf vulnerabilityInteger overflow in the GTK+ gdk-pixbuf XPM image rendering library in GTK+ 2.4.0 allows attackers to execute arbitrary code via an XPM file with a n…EPSS 4.7%7.5CVE-2005-0891Gnome gtk double free vulnerabilityDouble free vulnerability in gtk 2 (gtk2) before 2.2.4 allows remote attackers to cause a denial of service (crash) via a crafted BMP image.EPSS 3.5%

Source: NIST National Vulnerability Database (record CVE-2004-0783), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.