Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-5864

29
FAUCET Score

CVE-2006-5864 describes a stack-based buffer overflow in the ps_gettext function of GNU gv 3.6.2 and earlier, which can also affect products like Evince that utilize gv. This vulnerability allows user-assisted attackers to execute arbitrary code by crafting PostScript files with excessively long comments in headers such as DocumentMedia or DocumentPaperSizes. With a CVSS score of 5.1 (AV:N/AC:H/Au:N/C:P/I:P/A:P), exploitation requires user interaction and has a high attack complexity, but can lead to partial compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog, an ExploitDB entry exists for Evince, indicating public exploit code availability, though there is no evidence of active exploitation, and it has received minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
3.5.8CPE matchmatch criteria
cpe:2.3:a:gnu:gv:3.5.8:*:*:*:*:*:*:*
3.6.0CPE matchmatch criteria
cpe:2.3:a:gnu:gv:3.6.0:*:*:*:*:*:*:*
3.6.1CPE matchmatch criteria
cpe:2.3:a:gnu:gv:3.6.1:*:*:*:*:*:*:*
3.6.2CPE matchmatch criteria
cpe:2.3:a:gnu:gv:3.6.2:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

5.1MEDIUM

AV:N/AC:H/Au:N/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
HIGH
Authentication
NONE
Exploitability Score
4.9
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
14.84%
Probability of exploitation in next 30 days
EPSS Percentile
96.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
ExploitDB: EDB-2858 · Nov 28, 2006
This CVE's current EPSS score of 0.1484 is in the 96th percentile among its peer group of 19,955 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2006-5864Low

CVE-2006-5864 evince contains a buffer overflow in get_next_text()

Nov 29, 2006

References

secunia.com / advisories/22787
Vendor Advisory
secunia.com / advisories/22932
Vendor Advisory
secunia.com / advisories/23006
Vendor Advisory
secunia.com / advisories/23018
Vendor Advisory
secunia.com / advisories/23111
Vendor Advisory
secunia.com / advisories/23118
Vendor Advisory
secunia.com / advisories/23183
Vendor Advisory
secunia.com / advisories/23266
Vendor Advisory
secunia.com / advisories/23306
Vendor Advisory
secunia.com / advisories/23335
Vendor Advisory
secunia.com / advisories/23353
Vendor Advisory
secunia.com / advisories/23409
Vendor Advisory
secunia.com / advisories/23579
Vendor Advisory
secunia.com / advisories/24649
Vendor Advisory
secunia.com / advisories/24787
Vendor Advisory
security.gentoo.org / glsa/glsa-200611-20.xml
security.gentoo.org / glsa/glsa-200703-24.xml
security.gentoo.org / glsa/glsa-200704-06.xml
exchange.xforce.ibmcloud.com / vulnerabilities/30153
exchange.xforce.ibmcloud.com / vulnerabilities/30555
issues.rpath.com / browse/RPL-850
exploit-db.com / exploits/2858
debian.org / security/2006/dsa-1214
debian.org / security/2006/dsa-1243
kb.cert.org / vuls/id/352825
US Government Resource
mandriva.com / security/advisories
mandriva.com / security/advisories
novell.com / linux/security/advisories/2006_26_sr.html
novell.com / linux/security/advisories/2006_28_sr.html
novell.com / linux/security/advisories/2006_29_sr.html
securityfocus.com / archive/1/451057/100/0/threaded
securityfocus.com / archive/1/451422/100/200/threaded
securityfocus.com / archive/1/452868/100/0/threaded
securityfocus.com / bid/20978
Exploit
ubuntu.com / usn/usn-390-1
ubuntu.com / usn/usn-390-2
ubuntu.com / usn/usn-390-3
vupen.com / english/advisories/2006/4424
Vendor Advisory
vupen.com / english/advisories/2006/4747
Vendor Advisory