Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
marc.info/?l=bugtraq&m=108213873203477&w=2
marc.info/?l=bugtraq&m=108214147022626&w=2
secunia.com/advisories/11363
security.gentoo.org/glsa/glsa-200405-01.xml
security.gentoo.org/glsa/glsa-200405-04.xml
www.debian.org/security/2004/dsa-487
www.mandriva.com/security/advisories?name=MDKSA-2004:032
www.osvdb.org/5365
www.redhat.com/support/errata/RHSA-2004-157.html
www.redhat.com/support/errata/RHSA-2004-158.html
www.redhat.com/support/errata/RHSA-2004-159.html
www.redhat.com/support/errata/RHSA-2004-160.html
www.securityfocus.com/bid/10136
bugzilla.fedora.us/show_bug.cgi?id=1552
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1065
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10913