# CVE-2001-1413

## Summary

- **CVE ID:** CVE-2001-1413
- **Severity:** UNKNOWN
- **CVSS Score:** 0.45
- **CWE:** N/A
- **Published:** Oct 20, 2004
- **Last Modified:** Mar 16, 2026

## Description

Stack-based buffer overflow in the comprexx function for ncompress 4.2.4 and earlier, when used in situations that cross security boundaries (such as FTP server), may allow remote attackers to execute arbitrary code via a long filename argument.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](http://security.gentoo.org/glsa/glsa-200410-08.xml)
- [CNA](http://seclists.org/lists/vuln-dev/2001/Nov/0202.html)
- [CNA](http://www.redhat.com/support/errata/RHSA-2004-536.html)
- [CNA](http://www.kb.cert.org/vuls/id/176363)
- [CNA](https://exchange.xforce.ibmcloud.com/vulnerabilities/10619)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 9.03%
- **EPSS Percentile:** 92.5

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._