Lucene search

K
cve[email protected]CVE-2004-0179
HistoryJun 01, 2004 - 4:00 a.m.

CVE-2004-0179

2004-06-0104:00:00
CWE-134
web.nvd.nist.gov
23
cve-2004-0179
format string vulnerability
neon
cadaver
subversion
openoffice
webdav
remote code execution

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.8%

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

Affected configurations

NVD
Node
webdavneonRange0.19.00.24.5
AND
apacheopenoffice
OR
apachesubversion
OR
webdavcadaver
Node
debiandebian_linuxMatch3.0
CPENameOperatorVersion
webdav:neonwebdav neonlt0.24.5

References

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7.1 High

AI Score

Confidence

Low

0.006 Low

EPSS

Percentile

78.8%