CVE-2004-0990

Exp

Integer overflow in GD Graphics Library libgd 2.0.28 (libgd2), and possibly other versions, allows remote attackers to cause a denial of service and possibly execute arbitrary code via PNG image files with large image rows values that lead to a heap-based buffer overflow in the gdImageCreateFromPngCtx function, a different set of vulnerabilities than CVE-2004-0941.

Published: 2005-03-01 Last update: 2026-04-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2004-0990 is rated High Exploit Risk (89.1/100): CVSS Critical severity, with high exploitation likelihood (EPSS 21.21%, 96th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2004-0990

EDB-ID Source Kind Published Link
600 exploit_db edb 2004-10-26 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2004-0990

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-04-12 20.60% 21.21% +0.61%
2 2026-02-18 33.48% 20.60% -12.88%
3 2025-12-01 33.48%

Full EPSS history (11 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2004-0990

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
10.0 2.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C Click to expand
Access vector (AV:N)
Can be exploited remotely over network reachability.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:C)
Complete confidentiality impact.
Integrity impact (I:C)
Complete integrity impact.
Availability impact (A:C)
Complete availability impact.
10.0 10.0 [email protected]

Weakness enumeration for CVE-2004-0990

OS Trackers for CVE-2004-0990

vendor priority summary link
debian not yet assigned CVE-2004-0990 not yet assigned priority: Debian including 1 source packages (libgd2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2004-0990
redhat high https://access.redhat.com/security/cve/CVE-2004-0990
ubuntu medium CVE-2004-0990 medium priority: Ubuntu including 2 source packages (libgd, libgd2), 8 status rows across 4 suites (dapper, edgy, feisty, upstream): released 6, needs-triage 2. https://ubuntu.com/security/CVE-2004-0990

Affected software / configurations for CVE-2004-0990

Vendor Product Version Raw CPE
gd_graphics_library gdlib 1.8.4 cpe:2.3:a:gd_graphics_library:gdlib:1.8.4:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.1 cpe:2.3:a:gd_graphics_library:gdlib:2.0.1:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.15 cpe:2.3:a:gd_graphics_library:gdlib:2.0.15:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.20 cpe:2.3:a:gd_graphics_library:gdlib:2.0.20:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.21 cpe:2.3:a:gd_graphics_library:gdlib:2.0.21:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.22 cpe:2.3:a:gd_graphics_library:gdlib:2.0.22:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.23 cpe:2.3:a:gd_graphics_library:gdlib:2.0.23:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.26 cpe:2.3:a:gd_graphics_library:gdlib:2.0.26:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.27 cpe:2.3:a:gd_graphics_library:gdlib:2.0.27:*:*:*:*:*:*:*
gd_graphics_library gdlib 2.0.28 cpe:2.3:a:gd_graphics_library:gdlib:2.0.28:*:*:*:*:*:*:*
openpkg openpkg 2.1 cpe:2.3:a:openpkg:openpkg:2.1:*:*:*:*:*:*:*
openpkg openpkg 2.2 cpe:2.3:a:openpkg:openpkg:2.2:*:*:*:*:*:*:*
openpkg openpkg current cpe:2.3:a:openpkg:openpkg:current:*:*:*:*:*:*:*
gentoo linux cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
suse suse_linux 8.0 cpe:2.3:o:suse:suse_linux:8.0:*:*:*:*:*:*:*
suse suse_linux 8.1 cpe:2.3:o:suse:suse_linux:8.1:*:*:*:*:*:*:*
suse suse_linux 8.2 cpe:2.3:o:suse:suse_linux:8.2:*:*:*:*:*:*:*
suse suse_linux 9.0 cpe:2.3:o:suse:suse_linux:9.0:*:*:*:*:*:*:*
suse suse_linux 9.0 cpe:2.3:o:suse:suse_linux:9.0:*:x86_64:*:*:*:*:*
suse suse_linux 9.1 cpe:2.3:o:suse:suse_linux:9.1:*:*:*:*:*:*:*
suse suse_linux 9.2 cpe:2.3:o:suse:suse_linux:9.2:*:*:*:*:*:*:*
trustix secure_linux 1.5 cpe:2.3:o:trustix:secure_linux:1.5:*:*:*:*:*:*:*
trustix secure_linux 2.0 cpe:2.3:o:trustix:secure_linux:2.0:*:*:*:*:*:*:*
trustix secure_linux 2.1 cpe:2.3:o:trustix:secure_linux:2.1:*:*:*:*:*:*:*
trustix secure_linux 2.2 cpe:2.3:o:trustix:secure_linux:2.2:*:*:*:*:*:*:*

References for CVE-2004-0990

URL Tags
http://lists.suse.com/archive/suse-security-announce/2006-Feb/0001.html
http://marc.info/?l=bugtraq&m=109882489302099&w=2
http://secunia.com/advisories/18717
http://secunia.com/advisories/20824
http://secunia.com/advisories/20866
http://secunia.com/advisories/21050
http://secunia.com/advisories/23783
http://www.ciac.org/ciac/bulletins/p-071.shtml
http://www.debian.org/security/2004/dsa-589
http://www.debian.org/security/2004/dsa-591
http://www.debian.org/security/2004/dsa-601
http://www.debian.org/security/2004/dsa-602
http://www.mandriva.com/security/advisories?name=MDKSA-2004:132
http://www.mandriva.com/security/advisories?name=MDKSA-2006:113
http://www.mandriva.com/security/advisories?name=MDKSA-2006:114
http://www.mandriva.com/security/advisories?name=MDKSA-2006:122
http://www.osvdb.org/11190
http://www.redhat.com/support/errata/RHSA-2004-638.html
http://www.securityfocus.com/bid/11523 Patch Vendor Advisory
http://www.trustix.org/errata/2004/0058
https://exchange.xforce.ibmcloud.com/vulnerabilities/17866
https://issues.rpath.com/browse/RPL-939
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1260
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9952
https://www.ubuntu.com/usn/usn-11-1/
https://www.ubuntu.com/usn/usn-25-1/
cvelogic Threat Intelligence