Back
CVE-2005-3318
Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in products such as KchmViewer, allows attackers to execute arbitrary code, a different vulnerability than CVE-2005-2930.
Published: Oct 27, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (8)
| Vendor | Product | Version |
|---|---|---|
| jed_wing | chm_lib | 0.1 |
| jed_wing | chm_lib | 0.2 |
| jed_wing | chm_lib | 0.3 |
| jed_wing | chm_lib | 0.31 |
| jed_wing | chm_lib | 0.32 |
| jed_wing | chm_lib | 0.33 |
| jed_wing | chm_lib | 0.35 |
| jed_wing | chm_lib | 0.36 |
GitHub Security Advisory GHSA-238q-w3p2-vw4m
Buffer overflow in the _chm_decompress_block function in CHM lib (chmlib) before 0.37, as used in...
References (26)
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0536.html
- http://morte.jedrea.com/~jedwin/projects/chmlib/ Patch
- http://secunia.com/advisories/17325 Vendor Advisory
- http://secunia.com/advisories/17480 Vendor Advisory
- http://secunia.com/advisories/17775 Vendor Advisory
- http://secunia.com/advisories/17776 Vendor Advisory
- http://www.gentoo.org/security/en/glsa/glsa-200511-23.xml
- http://www.novell.com/linux/security/advisories/2005_25_sr.html
- http://www.osvdb.org/20335
- http://www.securityfocus.com/bid/15211 Patch
- http://www.sven-tantau.de/public_files/chmlib/chmlib_20051126.txt Patch, Vendor Advisory
- http://www.vupen.com/english/advisories/2005/2207
- https://exchange.xforce.ibmcloud.com/vulnerabilities/22885
- http://archives.neohapsis.com/archives/fulldisclosure/2005-10/0536.html
- http://morte.jedrea.com/~jedwin/projects/chmlib/ Patch
Risk Scores
CVSS Score
5.1 / 10
EPSS Score
3.78%
Top 11% most likely to be exploited
Threat Score
21.5 / 100
Data Sources
NVD
EPSS
GitHub