← All CVEs

CVE-2004-0493

medium · 6.4

The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memory exhaustion), and possibly an integer signedness error leading to a heap-based buffer overflow on 64 bit systems, via long header lines with large numbers of space or tab characters.

6.4
CVSS
84.8%
EPSS (exploit prob.)
100th
EPSS percentile
2004-08-06
Published

AV:N/AC:L/Au:N/C:N/I:P/A:P

Affected products

VendorProductAffected versions
avayaconverged_communications_server2.0
gentoolinux1.4
trustixsecure_linux1.5
trustixsecure_linux2.0
trustixsecure_linux2.1
apachehttp_server2.0.47
apachehttp_server2.0.48
apachehttp_server2.0.49
ibmhttp_server2.0.42
ibmhttp_server2.0.42.1
ibmhttp_server2.0.42.2
ibmhttp_server2.0.47
ibmhttp_server2.0.47.1
avayas8300r2.0.0
avayas8500r2.0.0
avayas8700r2.0.0

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-0493