← All CVEs

CVE-2004-0362

high · 7.5

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

7.5
CVSS
73.3%
EPSS (exploit prob.)
99th
EPSS percentile
2004-04-15
Published

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

VendorProductAffected versions
issblackice_agent_server3.6ebz
issblackice_agent_server3.6eca
issblackice_agent_server3.6ecb
issblackice_agent_server3.6ecc
issblackice_agent_server3.6ecd
issblackice_agent_server3.6ece
issblackice_agent_server3.6ecf
issblackice_pc_protection3.6cbz
issblackice_pc_protection3.6cca
issblackice_pc_protection3.6ccb
issblackice_pc_protection3.6ccc
issblackice_pc_protection3.6ccd
issblackice_pc_protection3.6cce
issblackice_pc_protection3.6ccf
issblackice_server_protection3.6cbz
issblackice_server_protection3.6cca
issblackice_server_protection3.6ccb
issblackice_server_protection3.6ccc
issblackice_server_protection3.6ccd
issblackice_server_protection3.6cce
issblackice_server_protection3.6ccf
issrealsecure_desktop3.6ebz
issrealsecure_desktop3.6eca
issrealsecure_desktop3.6ecb
issrealsecure_desktop3.6ecd
issrealsecure_desktop3.6ece
issrealsecure_desktop3.6ecf
issrealsecure_desktop7.0eba
issrealsecure_desktop7.0ebf
issrealsecure_desktop7.0ebg
issrealsecure_desktop7.0ebh
issrealsecure_desktop7.0ebj
issrealsecure_desktop7.0ebk
issrealsecure_desktop7.0ebl
issrealsecure_guard3.6ebz
issrealsecure_guard3.6eca
issrealsecure_guard3.6ecb
issrealsecure_guard3.6ecc
issrealsecure_guard3.6ecd
issrealsecure_guard3.6ece

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0362