Back

CVE-2004-2372

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute arbitrary code via a long HOME environment variable, which is used if the .bochsrc, bochsrc, and bochsrc.txt cannot be found in a known path. NOTE: some external documents recommend that Bochs be installed setuid root, so this should be treated as a vulnerability.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
bochs_project bochs * < 2.1.1

GitHub Security Advisory GHSA-g3hw-2h8v-79ff

Buffer overflow in Bochs before 2.1.1, if installed setuid, allows local users to execute...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.71%

Top 50% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub