6.8 Medium
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
AV:N/AC:M/Au:N/C:P/I:P/A:P
7.3 High
AI Score
Confidence
Low
0.006 Low
EPSS
Percentile
78.8%
Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
marc.info/?l=bugtraq&m=108213873203477&w=2
marc.info/?l=bugtraq&m=108214147022626&w=2
secunia.com/advisories/11363
security.gentoo.org/glsa/glsa-200405-01.xml
security.gentoo.org/glsa/glsa-200405-04.xml
www.debian.org/security/2004/dsa-487
www.mandriva.com/security/advisories?name=MDKSA-2004:032
www.osvdb.org/5365
www.redhat.com/support/errata/RHSA-2004-157.html
www.redhat.com/support/errata/RHSA-2004-158.html
www.redhat.com/support/errata/RHSA-2004-159.html
www.redhat.com/support/errata/RHSA-2004-160.html
www.securityfocus.com/bid/10136
bugzilla.fedora.us/show_bug.cgi?id=1552
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1065
oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10913