← Vulnerability feed

Vulnerability record · CVE-2004-1595 · published 13 October 2004

CVE-2004-1595: ShixxNote font field buffer overflow allows remote code execution

Shixxnote · Shixxnote

ShixxNote 6.net build 117 contains a buffer overflow in its handling of a font field. A remote attacker can send a crafted value that overflows the buffer, potentially leading to arbitrary code execution on the affected host. The record does not specify the exact protocol or message type carrying the font field.

7.5 CVSS 2.0 High EPSS 59% · top 0.9%
7.5CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityNetwork-reachable, unauthenticated buffer overflow with public exploit references and very high EPSS percentile, though no KEV listing or confirmed in-the-wild activity is recorded.

What it is

ShixxNote 6.net build 117 contains a buffer overflow in its handling of a font field. A remote attacker can send a crafted value that overflows the buffer, potentially leading to arbitrary code execution on the affected host. The record does not specify the exact protocol or message type carrying the font field.

Impact

An attacker who successfully triggers the overflow may execute arbitrary code in the context of the ShixxNote process, giving them control of the affected system.

Attack surface

The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether any user interaction is required to process the malicious font field.

Exploitation

CVE-2004-1595 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.5932 (99.075th percentile), and two references are tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor fix or upgrade ShixxNote past 6.net build 117; no patched version is named in the record, so confirm with the vendor.
  • If no fix is available, restrict network exposure of ShixxNote services to trusted hosts and block untrusted traffic to the affected port or interface.
  • Run ShixxNote with least privilege so a successful overflow does not yield administrative rights.
  • Monitor vendor and Secunia/SecurityFocus advisories for updated guidance, since the record is old and may be incomplete.

Detection

  • Inspect network traffic to ShixxNote for oversized or malformed font field values.
  • Monitor ShixxNote process crashes or abnormal termination events on endpoints.
  • Watch for unexpected child processes or code execution spawned by the ShixxNote process.
  • Review host logs for anomalous outbound connections originating from the ShixxNote process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1595 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2004-1595), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.