{
    "id": "CVE-2005-3491",
    "published": "2005-11-04 00:02:00",
    "last_modified": "2026-06-16 22:17:03",
    "cvss_score": "7.5",
    "cvss_severity": "HIGH",
    "cvss_version": "2.0",
    "cvss_vector": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
    "cwe": null,
    "description": "Multiple buffer overflows in the receiver function in loop.c in FlatFrag 0.3 and earlier allow remote attackers to execute arbitrary code via the (1) version, (2) name, and (3) model fields.",
    "epss_score": "0.04921",
    "epss_percentile": "0.91877",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-10-06 18:17:03",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "johannes_f._kuhlmann",
            "product": "flatfrag"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "1283",
            "title": "FlatFrag 0.3 - Buffer Overflow (Denial of Service) (PoC)",
            "date": "2005-11-02",
            "url": "https://www.exploit-db.com/exploits/1283"
        }
    ],
    "refs_list": [
        "http://aluigi.altervista.org/adv/flatfragz-adv.txt",
        "http://marc.info/?l=full-disclosure&m=113096078606274&w=2",
        "http://www.osvdb.org/20769",
        "http://www.securityfocus.com/archive/1/415636/30/0/threaded",
        "http://www.securityfocus.com/bid/15287",
        "http://aluigi.altervista.org/adv/flatfragz-adv.txt",
        "http://marc.info/?l=full-disclosure&m=113096078606274&w=2",
        "http://www.osvdb.org/20769",
        "http://www.securityfocus.com/archive/1/415636/30/0/threaded",
        "http://www.securityfocus.com/bid/15287"
    ]
}