Vulnerability record · CVE-2004-1595 · published 13 October 2004
CVE-2004-1595: ShixxNote font field buffer overflow allows remote code execution
Shixxnote · Shixxnote
ShixxNote 6.net build 117 contains a buffer overflow in its handling of a font field. A remote attacker can send a crafted value that overflows the buffer, potentially leading to arbitrary code execution on the affected host. The record does not specify the exact protocol or message type carrying the font field.
Description
Buffer overflow in ShixxNote 6.net build 117 allows remote attackers to execute arbitrary code via a long font field.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated buffer overflow with public exploit references and very high EPSS percentile, though no KEV listing or confirmed in-the-wild activity is recorded.
What it is
ShixxNote 6.net build 117 contains a buffer overflow in its handling of a font field. A remote attacker can send a crafted value that overflows the buffer, potentially leading to arbitrary code execution on the affected host. The record does not specify the exact protocol or message type carrying the font field.
Impact
An attacker who successfully triggers the overflow may execute arbitrary code in the context of the ShixxNote process, giving them control of the affected system.
Attack surface
The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and low complexity. The description does not state whether any user interaction is required to process the malicious font field.
Exploitation
CVE-2004-1595 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.5932 (99.075th percentile), and two references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor fix or upgrade ShixxNote past 6.net build 117; no patched version is named in the record, so confirm with the vendor.
- If no fix is available, restrict network exposure of ShixxNote services to trusted hosts and block untrusted traffic to the affected port or interface.
- Run ShixxNote with least privilege so a successful overflow does not yield administrative rights.
- Monitor vendor and Secunia/SecurityFocus advisories for updated guidance, since the record is old and may be incomplete.
Detection
- Inspect network traffic to ShixxNote for oversized or malformed font field values.
- Monitor ShixxNote process crashes or abnormal termination events on endpoints.
- Watch for unexpected child processes or code execution spawned by the ShixxNote process.
- Review host logs for anomalous outbound connections originating from the ShixxNote process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=109778648232233&w=2 | |
| http://secunia.com/advisories/12822/ | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/11409 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17705 | |
| http://marc.info/?l=bugtraq&m=109778648232233&w=2 | |
| http://secunia.com/advisories/12822/ | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/11409 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17705 |
Track CVE-2004-1595 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2004-1595), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.