Lucene search

K
cve[email protected]CVE-2004-0492
HistoryAug 06, 2004 - 4:00 a.m.

CVE-2004-0492

2004-08-0604:00:00
web.nvd.nist.gov
290
apache
mod_proxy
buffer overflow
cve-2004-0492
denial of service
remote code execution

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.5%

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

Affected configurations

NVD
Node
apachehttp_serverMatch1.3.26
OR
apachehttp_serverMatch1.3.27
OR
apachehttp_serverMatch1.3.28
OR
apachehttp_serverMatch1.3.29
OR
apachehttp_serverMatch1.3.31
OR
hpvirtualvaultMatch11.0.4
OR
hpwebproxyMatch2.0
OR
hpwebproxyMatch2.1
OR
ibmhttp_serverMatch1.3.26
OR
ibmhttp_serverMatch1.3.26.1
OR
ibmhttp_serverMatch1.3.26.2
OR
ibmhttp_serverMatch1.3.28
OR
sgipropackMatch2.4
Node
hpvvosMatch11.04
OR
openbsdopenbsd
OR
openbsdopenbsdMatch3.4
OR
openbsdopenbsdMatch3.5

References

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

8.1 High

AI Score

Confidence

High

0.012 Low

EPSS

Percentile

85.5%