CVE-2005-1219
UnknownEPSS 49.92%
Last modified
CVE-2005-1219 is a vulnerability of currently unknown severity. Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.. EPSS estimates a 49.92% chance of exploitation in the next 30 days.
Description
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.
Metrics
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Microsoft | Image Color Management | All versions | Gold |
References
- http://secunia.com/advisories/16004/Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/720742US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-193A.htmlUS Government Resource
- http://secunia.com/advisories/16004/Patch, Vendor Advisory
- http://www.kb.cert.org/vuls/id/720742US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA05-193A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2005-1219?
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.
How severe is CVE-2005-1219?
Severity scoring for CVE-2005-1219 is pending analysis. The EPSS model estimates a 49.92% probability of exploitation in the next 30 days.
How do I fix CVE-2005-1219?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2005
- CVE-2005-1212Buffer overflow in Microsoft Step-by-Step Interactive Traini…
- CVE-2005-1213Stack-based buffer overflow in the news reader for Microsoft…
- CVE-2005-1214Microsoft Agent allows remote attackers to spoof trusted Int…
- CVE-2005-1215Microsoft ISA Server 2000 allows remote attackers to poison …
- CVE-2005-1216Microsoft ISA Server 2000 allows remote attackers to connect…
- CVE-2005-1218The Microsoft Windows kernel in Microsoft Windows 2000 Serve…
- CVE-2005-1220Shoutbox SCRIPT 3.0.2 and earlier allows remote attackers to…
- CVE-2005-1221SQL injection vulnerability in login.asp for Ecommerce-Carts…
- CVE-2005-1222cat_for_gen.php in Annuaire Netref 4.2 allows remote attacke…
- CVE-2005-1223Multiple SQL injection vulnerabilities in Ocean12 Calendar m…
- CVE-2005-1224Multiple SQL injection vulnerabilities in DUware DUportal Pr…
- CVE-2005-1225SQL injection vulnerability in Coppermine Photo Gallery 1.3.…
Are you affected by CVE-2005-1219?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
