{"api_version":"1","generated_at":"2026-07-23T10:16:42+00:00","cve":"CVE-2005-3891","urls":{"html":"https://cve.report/CVE-2005-3891","api":"https://cve.report/api/cve/CVE-2005-3891.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-3891","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-3891"},"summary":{"title":"CVE-2005-3891","description":"Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the \"imgcache\\\" string that is added to the end of the buffer.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-11-29 21:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/17597/","name":"http://secunia.com/advisories/17597/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Secunia - Advisories - Gadu-Gadu Multiple Vulnerabilities and Weaknesses","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/21016","name":"http://www.osvdb.org/21016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=113261573023912&w=2","name":"http://marc.info/?l=bugtraq&m=113261573023912&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"'Gadu-Gadu several vulnerabilities (version <= 7.20)' - MARC","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html","name":"http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Neohapsis Archives - Full Disclosure List - #0658 - [Full-disclosure] Gadu-Gadu several vulnerabilities (version <= 7.20)","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15520/","name":"http://www.securityfocus.com/bid/15520/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Gadu-Gadu Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23149","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/15520","name":"BID:15520","refsource":"MITRE","tags":[],"title":"Gadu-Gadu Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-3891","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-3891","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"3891","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gadu-gadu","cpe5":"gadu-gadu_instant_messenger","cpe6":"7.20","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T23:24:36.533Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"15520","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/15520/"},{"name":"21016","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/21016"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=113261573023912&w=2"},{"name":"17597","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/17597/"},{"name":"gadu-gadu-image-name-bo(23149)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23149"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-11-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the \"imgcache\\\" string that is added to the end of the buffer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"15520","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/15520/"},{"name":"21016","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/21016"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=113261573023912&w=2"},{"name":"17597","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/17597/"},{"name":"gadu-gadu-image-name-bo(23149)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23149"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-3891","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the \"imgcache\\\" string that is added to the end of the buffer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"15520","refsource":"BID","url":"http://www.securityfocus.com/bid/15520/"},{"name":"21016","refsource":"OSVDB","url":"http://www.osvdb.org/21016"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=113261573023912&w=2"},{"name":"17597","refsource":"SECUNIA","url":"http://secunia.com/advisories/17597/"},{"name":"gadu-gadu-image-name-bo(23149)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23149"},{"name":"20051121 Gadu-Gadu several vulnerabilities (version <= 7.20)","refsource":"FULLDISC","url":"http://archives.neohapsis.com/archives/fulldisclosure/2005-11/0658.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-3891","datePublished":"2005-11-29T21:00:00.000Z","dateReserved":"2005-11-29T00:00:00.000Z","dateUpdated":"2024-08-07T23:24:36.533Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-11-29 21:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gadu-gadu:gadu-gadu_instant_messenger:7.20:*:*:*:*:*:*:*","matchCriteriaId":"669DCBF2-8C36-4AC4-8C45-2E36700645FF"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"3891","Ordinal":"1","Title":"CVE-2005-3891","CVE":"CVE-2005-3891","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"3891","Ordinal":"1","NoteData":"Stack-based buffer overflow in Gadu-Gadu 7.20 allows remote attackers to cause a denial of service (crash) via an image filename between exactly 192 to 200 characters, which does not account for the \"imgcache\\\" string that is added to the end of the buffer.","Type":"Description","Title":"CVE-2005-3891"},{"CveYear":"2005","CveId":"3891","Ordinal":"2","NoteData":"2005-11-29","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"3891","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}