← Vulnerability feed

Vulnerability record · CVE-2006-2480 · published 19 May 2006

CVE-2006-2480: Dia vulnerability

Dia · Dia

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

5.1 CVSS 2.0 Medium EPSS 7.6% · top 5.6% CWE-134 · CWE-134
5.1CVSS 2.0 base score
7.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
38References, 6 tagged exploit
16 Jun 2026Last modified by NVD

Description

Format string vulnerability in Dia 0.94 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering errors or warnings, as demonstrated via format string specifiers in a .bmp filename. NOTE: the original exploit was demonstrated through a command line argument, but there are other mechanisms for input that are automatically processed by Dia, such as a crafted .dia file.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugzilla.gnome.org/show_bug.cgi?id=342111 Exploit
http://kandangjamur.net/tutorial/dia.txt Exploit
http://secunia.com/advisories/20199 Vendor Advisory
http://secunia.com/advisories/20254 PatchVendor Advisory
http://secunia.com/advisories/20339 Vendor Advisory
http://secunia.com/advisories/20422 Vendor Advisory
http://secunia.com/advisories/20457 Vendor Advisory
http://secunia.com/advisories/20513 Vendor Advisory
http://securitytracker.com/id?1016203
http://www.gentoo.org/security/en/glsa/glsa-200606-03.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:093
http://www.novell.com/linux/security/advisories/2006-06-02.html Vendor Advisory
http://www.osvdb.org/25699
http://www.redhat.com/support/errata/RHSA-2006-0541.html Vendor Advisory
http://www.securityfocus.com/archive/82/433313/30/0/threaded Exploit
http://www.securityfocus.com/bid/18078
http://www.vupen.com/english/advisories/2006/1908 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11224
https://usn.ubuntu.com/286-1/
http://bugzilla.gnome.org/show_bug.cgi?id=342111 Exploit
http://kandangjamur.net/tutorial/dia.txt Exploit
http://secunia.com/advisories/20199 Vendor Advisory
http://secunia.com/advisories/20254 PatchVendor Advisory
http://secunia.com/advisories/20339 Vendor Advisory
http://secunia.com/advisories/20422 Vendor Advisory
http://secunia.com/advisories/20457 Vendor Advisory
http://secunia.com/advisories/20513 Vendor Advisory
http://securitytracker.com/id?1016203
http://www.gentoo.org/security/en/glsa/glsa-200606-03.xml
http://www.mandriva.com/security/advisories?name=MDKSA-2006:093
http://www.novell.com/linux/security/advisories/2006-06-02.html Vendor Advisory
http://www.osvdb.org/25699
http://www.redhat.com/support/errata/RHSA-2006-0541.html Vendor Advisory
http://www.securityfocus.com/archive/82/433313/30/0/threaded Exploit
http://www.securityfocus.com/bid/18078
http://www.vupen.com/english/advisories/2006/1908 Vendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11224
https://usn.ubuntu.com/286-1/

Track CVE-2006-2480 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.6CVE-2006-1550Dia memory buffer overflow vulnerabilityMultiple buffer overflows in the xfig import code (xfig-import.c) in Dia 0.87 and later before 0.95-pre6 allow user-assisted attackers to have an unk…EPSS 2.5%7.5CVE-2007-3408Dia vulnerabilityMultiple unspecified vulnerabilities in Dia before 0.96.1-6 have unspecified attack vectors and impact, probably involving the use of vulnerable Free…EPSS 1.2%7.5CVE-2006-2453Dia vulnerabilityMultiple unspecified format string vulnerabilities in Dia have unspecified impact and attack vectors, a different set of issues than CVE-2006-2480.EPSS 2.2%6.9CVE-2008-5984Dia vulnerabilityUntrusted search path vulnerability in the Python plugin in Dia 0.96.1, and possibly other versions, allows local users to execute arbitrary code via…EPSS 0.40%5.1CVE-2005-2966Dia vulnerabilityThe Python SVG import plugin (diasvg_import.py) for DIA 0.94 and earlier allows user-assisted attackers to execute arbitrary commands via a crafted S…EPSS 2.6%9.8CVE-2024-23113Fortinet FortiOS and related products format string remote code executionA use of externally-controlled format string (CWE-134) in Fortinet FortiOS, FortiProxy, FortiPAM and FortiSwitchManager lets an attacker execute unau…KEVEPSS 62%analysed5.5CVE-2021-25489Samsung Android modem driver format string bug causes kernel panicSamsung Android devices contain a missing input validation flaw in the modem interface driver, resulting in a format string bug. It is listed in CISA…KEVEPSS 0.53%analysed8.0CVE-2018-0175Cisco IOS, IOS XE and IOS XR LLDP format string flawA format string vulnerability exists in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS, IOS XE and IOS XR Software. An unauthenticat…KEVEPSS 3.5%analysed

Source: NIST National Vulnerability Database (record CVE-2006-2480), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.