Back

CVE-2005-1394

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain privileges via format string specifiers in the ARCHOME environment variable to (1) wservice or (2) lockmgr.

Published: May 3, 2005 Modified: Jun 16, 2026
CWE-134

CVSS Metrics

Affected Products (1)

Vendor Product Version
esri arcinfo_workstation 9.0

GitHub Security Advisory GHSA-fcmj-qrc7-5x9g

Format string vulnerability in ArcGIS for ESRI ArcInfo Workstation 9.0 allows local users to gain...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.83%

Top 45% most likely to be exploited

Threat Score 29 / 100

Data Sources

NVD EPSS GitHub