← Vulnerability feed

Vulnerability record · CVE-2004-1232 · published 10 January 2005

CVE-2004-1232: Gadu-gadu instant messenger vulnerability

GGadu Gadu · Gadu Gadu Instant Messenger

Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.

10.0 CVSS 2.0 High EPSS 6.2% · top 6.7%
10.0CVSS 2.0 base score
6.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the code that sends images in Gadu-Gadu allows remote attackers to execute arbitrary code via a large image filename.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1232 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2005-3888Gadu-gadu instant messenger vulnerabilityMemory leak in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service via multiple DCC packets with a code other than 2 and a large size…EPSS 2.2%7.8CVE-2005-3890Gadu-gadu instant messenger vulnerabilityGadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash and configuration loss) via a page with a large number of gg: URIs.EPSS 2.1%7.8CVE-2005-3891Gadu-gadu instant messenger vulnerabilityStack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 …EPSS 2.3%7.5CVE-2004-1229Gadu-gadu instant messenger vulnerabilityCross-site scripting vulnerability in the parser for Gadu-Gadu allows remote attackers to inject arbitrary web script or HTML via (1) http:// or (2) …EPSS 1.6%7.5CVE-2004-1676Gadu-gadu instant messenger vulnerabilityHeap-based buffer overflow in the image sending feature in Gadu-Gadu 6.0 build 149 allows remote attackers to execute arbitrary code via a crafted GG…EPSS 3.3%5.4CVE-2005-3887Gadu-gadu instant messenger vulnerabilityGadu-Gadu 7.20 does not properly handle MS-DOS device names in filenames, which allows remote attackers to (1) cause a denial of service (hang) via a…EPSS 1.9%5.0CVE-2005-3892Gadu-gadu instant messenger vulnerabilityGadu-Gadu 7.20 allows remote attackers to eavesdrop on a user via a web page that accesses the EasycallLite.oce ActiveX control, which can initiate a…EPSS 1.4%5.0CVE-2004-1230Gadu-gadu instant messenger vulnerabilityGadu-Gadu allows remote attackers to gain sensitive information and read files from the _cache directory of other users via a DCC connection and a CT…EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2004-1232), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.