// For flags

CVE-2004-0996

Cscope 13.0/15.x - Insecure Temporary File Creation

Severity Score

2.1
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

main.c in cscope 15-4 and 15-5 creates temporary files with predictable filenames, which allows local users to overwrite arbitrary files via a symlink attack.

main.c de cscope 15-4 y 15-5 crea ficheros temporales con nombres predecibles, lo que permite a usuarios locales sobreescribir ficheros de su elección mediante un ataque de enlaces simbólicos.

*Credits: N/A
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2004-11-02 CVE Reserved
  • 2004-11-17 First Exploit
  • 2004-12-01 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-08 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Cscope
Search vendor "Cscope"
Cscope
Search vendor "Cscope" for product "Cscope"
13.0
Search vendor "Cscope" for product "Cscope" and version "13.0"
-
Affected
Cscope
Search vendor "Cscope"
Cscope
Search vendor "Cscope" for product "Cscope"
15.1
Search vendor "Cscope" for product "Cscope" and version "15.1"
-
Affected
Cscope
Search vendor "Cscope"
Cscope
Search vendor "Cscope" for product "Cscope"
15.3
Search vendor "Cscope" for product "Cscope" and version "15.3"
-
Affected
Cscope
Search vendor "Cscope"
Cscope
Search vendor "Cscope" for product "Cscope"
15.4
Search vendor "Cscope" for product "Cscope" and version "15.4"
-
Affected
Cscope
Search vendor "Cscope"
Cscope
Search vendor "Cscope" for product "Cscope"
15.5
Search vendor "Cscope" for product "Cscope" and version "15.5"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
-
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
alpha
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
arm
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
hppa
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
ia-32
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
ia-64
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
m68k
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
mips
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
mipsel
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
ppc
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
s-390
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
3.0
Search vendor "Debian" for product "Debian Linux" and version "3.0"
sparc
Affected
Gentoo
Search vendor "Gentoo"
Linux
Search vendor "Gentoo" for product "Linux"
*-
Affected
Sco
Search vendor "Sco"
Unixware
Search vendor "Sco" for product "Unixware"
7.1.1
Search vendor "Sco" for product "Unixware" and version "7.1.1"
-
Affected
Sco
Search vendor "Sco"
Unixware
Search vendor "Sco" for product "Unixware"
7.1.3
Search vendor "Sco" for product "Unixware" and version "7.1.3"
-
Affected
Sco
Search vendor "Sco"
Unixware
Search vendor "Sco" for product "Unixware"
7.1.4
Search vendor "Sco" for product "Unixware" and version "7.1.4"
-
Affected