{"api_version":"1","generated_at":"2026-07-23T06:43:48+00:00","cve":"CVE-2005-3831","urls":{"html":"https://cve.report/CVE-2005-3831","api":"https://cve.report/api/cve/CVE-2005-3831.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3831","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3831"},"summary":{"title":"CVE-2005-3831","description":"Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-26 19:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.1","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1015266","name":"http://securitytracker.com/id?1015266","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - Squeez Buffer Overflows in Processing ZIP/UUE Files May Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/417588/30/0/threaded","name":"http://www.securityfocus.com/archive/1/417588/30/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2005-60/advisory","name":"http://secunia.com/secunia_research/2005-60/advisory","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2005/2570","name":"http://www.vupen.com/english/advisories/2005/2570","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/17420","name":"http://secunia.com/advisories/17420","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - SpeedProject Products ZIP/UUE File Extraction Buffer Overflow","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21073","name":"http://www.osvdb.org/21073","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015267","name":"http://securitytracker.com/id?1015267","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - SpeedCommander Buffer Overflows in Processing ZIP/UUE Files May Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015265","name":"http://securitytracker.com/id?1015265","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - ZipStar Buffer Overflow in Processing ZIP Files May Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3831","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3831","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3831","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"speedproject","cpe5":"speedcommander","cpe6":"10.51_build4430","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3831","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"speedproject","cpe5":"speedcommander","cpe6":"11.0_build4430","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3831","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"speedproject","cpe5":"squeez","cpe6":"5.0_build_4285","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"3831","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"speedproject","cpe5":"zipstar","cpe6":"5.0_build_4285","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.381Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2005-60/advisory"},{"name":"1015265","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015265"},{"name":"ADV-2005-2570","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2005/2570"},{"name":"1015267","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015267"},{"name":"20051124 Secunia Research: SpeedProject Products ZIP/UUE File ExtractionBuffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/417588/30/0/threaded"},{"name":"21073","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21073"},{"name":"17420","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17420"},{"name":"1015266","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015266"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2005-60/advisory"},{"name":"1015265","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015265"},{"name":"ADV-2005-2570","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2005/2570"},{"name":"1015267","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015267"},{"name":"20051124 Secunia Research: SpeedProject Products ZIP/UUE File ExtractionBuffer Overflow","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/417588/30/0/threaded"},{"name":"21073","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21073"},{"name":"17420","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17420"},{"name":"1015266","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015266"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3831","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://secunia.com/secunia_research/2005-60/advisory","refsource":"MISC","url":"http://secunia.com/secunia_research/2005-60/advisory"},{"name":"1015265","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015265"},{"name":"ADV-2005-2570","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2005/2570"},{"name":"1015267","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015267"},{"name":"20051124 Secunia Research: SpeedProject Products ZIP/UUE File ExtractionBuffer Overflow","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/417588/30/0/threaded"},{"name":"21073","refsource":"OSVDB","url":"http://www.osvdb.org/21073"},{"name":"17420","refsource":"SECUNIA","url":"http://secunia.com/advisories/17420"},{"name":"1015266","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015266"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3831","datePublished":"2005-11-26T19:00:00.000Z","dateReserved":"2005-11-26T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.381Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-26 19:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:speedproject:speedcommander:10.51_build4430:*:*:*:*:*:*:*","matchCriteriaId":"B3DDD6C4-9A56-479D-8E0B-2FE579C64387"},{"vulnerable":true,"criteria":"cpe:2.3:a:speedproject:speedcommander:11.0_build4430:*:*:*:*:*:*:*","matchCriteriaId":"53E30983-D8AC-46AE-B779-BCDBC40DF5BC"},{"vulnerable":true,"criteria":"cpe:2.3:a:speedproject:squeez:5.0_build_4285:*:*:*:*:*:*:*","matchCriteriaId":"8E8A7318-F5C2-4A74-83B5-80BDEFCDF1C3"},{"vulnerable":true,"criteria":"cpe:2.3:a:speedproject:zipstar:5.0_build_4285:*:*:*:*:*:*:*","matchCriteriaId":"BDC48414-ECB2-42E2-9EBE-F88FA8D1C846"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3831","Ordinal":"1","Title":"CVE-2005-3831","CVE":"CVE-2005-3831","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3831","Ordinal":"1","NoteData":"Stack-based buffer overflow in (1) CxZIP60.dll and (2) CxZIP60u.dll, as used in SpeedProject products including (a) ZipStar 5.0 Build 4285, (b) Squeez 5.0 Build 4285, and (c) SpeedCommander 11.0 Build 4430 and 10.51 Build 4430, allows user-assisted attackers to execute arbitrary code via a ZIP archive containing a long filename.","Type":"Description","Title":"CVE-2005-3831"},{"CveYear":"2005","CveId":"3831","Ordinal":"2","NoteData":"2005-11-26","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3831","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}