Back
CVE-2005-1394
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.
Published: May 3, 2005
Modified: Jun 16, 2026
CWE-134
CVSS Metrics
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| esri | arcinfo_workstation | 9.0 |
GitHub Security Advisory GHSA-fcmj-qrc7-5x9g
Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain...
References (10)
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2 Mailing List, Third Party Advisory
- http://secunia.com/advisories/15196 Broken Link
- http://securitytracker.com/id?1013852 Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015 Vendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt Patch, Third Party Advisory
- http://marc.info/?l=full-disclosure&m=111489411524630&w=2 Mailing List, Third Party Advisory
- http://secunia.com/advisories/15196 Broken Link
- http://securitytracker.com/id?1013852 Broken Link, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://support.esri.com/index.cfm?fa=downloads.patchesServicePacks.viewPatch&PID=14&MetaID=1015 Vendor Advisory
- http://www.digitalmunition.com/DMA%5B2005-0425a%5D.txt Patch, Third Party Advisory
Risk Scores
CVSS Score
7.2 / 10
EPSS Score
0.83%
Top 45% most likely to be exploited
Threat Score
29 / 100
Data Sources
NVD
EPSS
GitHub