CVE-2005-3154

BitDefender AntiVirus 7.2-9 - Remote Code Execution via Format String in File or Directory Name

Title source: llm
STIX 2.1

Description

Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.

References (5)

Core 5
Core References
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/16991
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/45
Third Party Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/14968

Scores

EPSS 0.0355
EPSS Percentile 87.8%

Details

CWE
CWE-134
Status published
Products (3)
softwin/bitdefender 7.2
softwin/bitdefender 8.0
softwin/bitdefender 9.0
Published Oct 05, 2005
Tracked Since Feb 18, 2026