Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-2480

27
FAUCET Score

CVE-2006-2480 describes a format string vulnerability in Dia 0.94, a diagramming software. This flaw allows user-assisted attackers to trigger a denial of service (crash) and potentially execute arbitrary code by embedding format string specifiers in filenames, such as a .bmp file. The vulnerability has a CVSS score of 5.1, indicating a medium severity, with a network attack vector and high attack complexity, leading to potential partial confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation, exploit code is publicly available through ExploitDB, and the vulnerability has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
0.94CPE matchmatch criteria
cpe:2.3:a:dia:dia:0.94:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.63%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
ExploitDB: EDB-27903 · May 23, 2006
This CVE's current EPSS score of 0.0763 is in the 93rd percentile among its peer group of 19,953 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: dia-1:0.94-5.7.1
View patch

Vendor Advisories (1)

redhatCVE-2006-2480Low

security flaw

May 10, 2004

References

bugzilla.gnome.org / show_bug.cgi
Exploit
kandangjamur.net / tutorial/dia.txt
Exploit
secunia.com / advisories/20199
Vendor Advisory
secunia.com / advisories/20254
PatchVendor Advisory
secunia.com / advisories/20339
Vendor Advisory
secunia.com / advisories/20422
Vendor Advisory
secunia.com / advisories/20457
Vendor Advisory
secunia.com / advisories/20513
Vendor Advisory
securitytracker.com / id
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11224
usn.ubuntu.com / 286-1
gentoo.org / security/en/glsa/glsa-200606-03.xml
mandriva.com / security/advisories
novell.com / linux/security/advisories/2006-06-02.html
Vendor Advisory
osvdb.org / 25699
redhat.com / support/errata/RHSA-2006-0541.html
Vendor Advisory
securityfocus.com / archive/82/433313/30/0/threaded
Exploit
securityfocus.com / bid/18078
vupen.com / english/advisories/2006/1908
Vendor Advisory