Back
CVE-2005-3154
Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9 allows remote attackers to cause a denial of service and possibly execute arbitrary code via format string specifiers in file or directory name.
Published: Oct 5, 2005
Modified: Jun 16, 2026
CWE-134
CVSS Metrics
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| softwin | bitdefender | 7.2 |
| softwin | bitdefender | 8.0 |
| softwin | bitdefender | 9.0 |
GitHub Security Advisory GHSA-vfx7-5239-r253
Format string vulnerability in the logging functionality in BitDefender AntiVirus 7.2 through 9...
References (10)
- http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html Broken Link
- http://secunia.com/advisories/16991 Permissions Required
- http://securityreason.com/securityalert/45 Third Party Advisory
- http://shadock.net/secubox/BitDefenderLoggingFunc.html Broken Link
- http://www.securityfocus.com/bid/14968 Third Party Advisory
- http://kb.bitdefender.com/KB261-en--Filename-Format-String-Vulnerability.html Broken Link
- http://secunia.com/advisories/16991 Permissions Required
- http://securityreason.com/securityalert/45 Third Party Advisory
- http://shadock.net/secubox/BitDefenderLoggingFunc.html Broken Link
- http://www.securityfocus.com/bid/14968 Third Party Advisory
Risk Scores
CVSS Score
7.5 / 10
EPSS Score
3.55%
Top 12% most likely to be exploited
Threat Score
31.1 / 100
Data Sources
NVD
EPSS
GitHub