CVE-2004-0179
medium · 6.8Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
6.8
CVSS
11.1%
EPSS (exploit prob.)
96th
EPSS percentile
2004-06-01
Published
AV:N/AC:M/Au:N/C:P/I:P/A:P
Weaknesses
CWE-134
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| webdav | neon | >= 0.19.0, < 0.24.5 |
| apache | openoffice | all versions |
| apache | subversion | all versions |
| webdav | cadaver | all versions |
| debian | debian_linux | 3.0 |
Check a specific version with /api/v1/cve/match.
References
- ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
- http://marc.info/?l=bugtraq&m=108213873203477&w=2
- http://marc.info/?l=bugtraq&m=108214147022626&w=2
- http://secunia.com/advisories/11363
- http://security.gentoo.org/glsa/glsa-200405-01.xml
- http://security.gentoo.org/glsa/glsa-200405-04.xml
- http://www.debian.org/security/2004/dsa-487
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:032
- http://www.osvdb.org/5365
- http://www.redhat.com/support/errata/RHSA-2004-157.html
- http://www.redhat.com/support/errata/RHSA-2004-158.html
- http://www.redhat.com/support/errata/RHSA-2004-159.html
- http://www.redhat.com/support/errata/RHSA-2004-160.html
- http://www.securityfocus.com/bid/10136
- https://bugzilla.fedora.us/show_bug.cgi?id=1552
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1065
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10913
- ftp://patches.sgi.com/support/free/security/advisories/20040404-01-U.asc
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0002.html
- http://lists.suse.com/archive/suse-security-announce/2004-Apr/0003.html
- http://marc.info/?l=bugtraq&m=108213873203477&w=2
- http://marc.info/?l=bugtraq&m=108214147022626&w=2
- http://secunia.com/advisories/11363
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2004-0179