Lucene search

K
cveMitreCVE-2004-1120
HistoryJan 10, 2005 - 5:00 a.m.

CVE-2004-1120

2005-01-1005:00:00
mitre
web.nvd.nist.gov
33
buffer overflow
network protocol
prozilla
remote code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.011

Percentile

84.6%

Multiple buffer overflows in (1) http.c, (2) http-retr.c, (3) main.c and other code that handles network protocols in ProZilla 1.3.6-r2 and earlier allow remote servers to execute arbitrary code via a long Location header.

Affected configurations

Nvd
Node
prozillaprozilla_download_acceleratorMatch1.0.0
OR
prozillaprozilla_download_acceleratorMatch1.3.0
OR
prozillaprozilla_download_acceleratorMatch1.3.1
OR
prozillaprozilla_download_acceleratorMatch1.3.2
OR
prozillaprozilla_download_acceleratorMatch1.3.3
OR
prozillaprozilla_download_acceleratorMatch1.3.4
OR
prozillaprozilla_download_acceleratorMatch1.3.5
OR
prozillaprozilla_download_acceleratorMatch1.3.5.1
OR
prozillaprozilla_download_acceleratorMatch1.3.5.2
OR
prozillaprozilla_download_acceleratorMatch1.3.6
VendorProductVersionCPE
prozillaprozilla_download_accelerator1.0.0cpe:2.3:a:prozilla:prozilla_download_accelerator:1.0.0:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.0cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.0:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.1cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.1:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.2cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.2:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.3cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.3:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.4cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.4:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.5cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.5:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.5.1cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.5.1:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.5.2cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.5.2:*:*:*:*:*:*:*
prozillaprozilla_download_accelerator1.3.6cpe:2.3:a:prozilla:prozilla_download_accelerator:1.3.6:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.3

Confidence

Low

EPSS

0.011

Percentile

84.6%