Back
CVE-2005-0240
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code via format string specifiers in a command line argument, which is not properly handled when printing an error message.
Published: May 2, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| ibm | aix | 5.2 |
GitHub Security Advisory GHSA-vghg-wg87-m285
Format string vulnerability in chdev on IBM AIX 5.2 allows local users to execute arbitrary code...
References (8)
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455 Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654 Vendor Advisory
- http://www.idefense.com/application/poi/display?type=vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19244
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY67455 Vendor Advisory
- http://www-1.ibm.com/support/docview.wss?uid=isg1IY67654 Vendor Advisory
- http://www.idefense.com/application/poi/display?type=vulnerabilities
- https://exchange.xforce.ibmcloud.com/vulnerabilities/19244
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.39%
Top 68% most likely to be exploited
Threat Score
28.9 / 100
Data Sources
NVD
EPSS
GitHub