Lucene search

K
cve[email protected]CVE-2004-0398
HistoryJul 07, 2004 - 4:00 a.m.

CVE-2004-0398

2004-07-0704:00:00
CWE-787
web.nvd.nist.gov
57
cve-2004-0398
buffer overflow
ne_rfc1036_parse
libneon
webdav
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.6%

Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.

Affected configurations

NVD
Node
webdavcadaverRange<0.22.0
OR
webdavneonRange0.24.5
Node
debiandebian_linuxMatch3.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7.6 High

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.6%