← Vulnerability feed

Vulnerability record · CVE-2005-0503 · published 21 February 2005

CVE-2005-0503: Uim vulnerability

Uim · Uim

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

4.6 CVSS 2.0 Medium EPSS 0.36% · top 72.4%
4.6CVSS 2.0 base score
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0503 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-3625Easy software products cups vulnerabilityXpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of servic…EPSS 3.8%10.0CVE-2004-1188Mplayer vulnerabilityThe pnm_get_chunk function in xine 0.99.2 and earlier, and other packages such as MPlayer that use the same code, does not properly verify that the c…EPSS 2.0%10.0CVE-2004-1187Mplayer vulnerabilityHeap-based buffer overflow in the pnm_get_chunk function for xine 0.99.2, and other packages such as MPlayer that use the same code, allows remote at…EPSS 5.2%10.0CVE-2004-0461Infoblox dns one appliance vulnerabilityThe DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C includ…EPSS 17%10.0CVE-2004-0460ISC DHCP dhcpd logging buffer overflow via hostname optionsISC DHCP 3.0.1rc12 and 3.0.1rc13 contain a buffer overflow in the DHCP daemon's logging capability. Multiple hostname options in DISCOVER, OFFER, REQ…EPSS 45%analysed10.0CVE-2004-0386Mplayer vulnerabilityBuffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Locat…EPSS 27%10.0CVE-2003-0041Mit kerberos ftp client os command injection vulnerabilityKerberos FTP client allows remote FTP sites to execute arbitrary code via a pipe (|) character in a filename that is retrieved by the client.EPSS 3.5%10.0CVE-2001-0388Freebsd vulnerabilitytime server daemon timed allows remote attackers to cause a denial of service via malformed packets.EPSS 2.7%

Source: NIST National Vulnerability Database (record CVE-2005-0503), CISA KEV, FIRST EPSS (scores of 2026-10-06). This page is refreshed as NVD updates the record.