CVE-2004-1301

Xlreader - Buffer Overflow

Title source: rule
STIX 2.1

Description

Buffer overflow in the book_format_sql function in format.c for xlreader 0.9.0 allows remote attackers to execute arbitrary code via a crafted Excel (XLS) file.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Kris Kubicki · textremotemultiple
https://www.exploit-db.com/exploits/24979

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18612
Exploit, Vendor Advisory x_refsource_misc
http://tigger.uic.edu/~jlongs2/holes/xlreader.txt

Scores

EPSS 0.2060
EPSS Percentile 95.7%

Details

Status published
Products (1)
xlreader/xlreader 0.9
Published Jan 10, 2005
Tracked Since Feb 18, 2026