CVE-2004-0416
Remote CVS 1.11.15 - 'error_prog_name' Arbitrary Code Execution
Severity Score
9.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Double free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to execute arbitrary code.
Vulnerabilidad de doble liberación en la cadena error_prog_name en CVS 1.12.x a 1.12.8, y 1.11.x a 1.11.16, puede permitir a atacantes remotos ejecutar código arbitrario.
A team audit of the CVS codebase has revealed more security related problems. The vulnerabilities discovered include exploitable, potentially exploitable and simple crash bugs. Vulnerable versions are CVS feature releases up to 1.12.8 and stable release up to 1.11.16.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-04-16 CVE Reserved
- 2004-06-10 CVE Published
- 2017-11-16 First Exploit
- 2024-08-08 CVE Updated
- 2025-05-29 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (14)
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/392 | 2017-11-16 |
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2004/dsa-519 | 2018-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.10.7 Search vendor "Cvs" for product "Cvs" and version "1.10.7" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.10.8 Search vendor "Cvs" for product "Cvs" and version "1.10.8" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11 Search vendor "Cvs" for product "Cvs" and version "1.11" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.1 Search vendor "Cvs" for product "Cvs" and version "1.11.1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.1_p1 Search vendor "Cvs" for product "Cvs" and version "1.11.1_p1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.2 Search vendor "Cvs" for product "Cvs" and version "1.11.2" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.3 Search vendor "Cvs" for product "Cvs" and version "1.11.3" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.4 Search vendor "Cvs" for product "Cvs" and version "1.11.4" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.5 Search vendor "Cvs" for product "Cvs" and version "1.11.5" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.6 Search vendor "Cvs" for product "Cvs" and version "1.11.6" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.10 Search vendor "Cvs" for product "Cvs" and version "1.11.10" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.11 Search vendor "Cvs" for product "Cvs" and version "1.11.11" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.14 Search vendor "Cvs" for product "Cvs" and version "1.11.14" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.15 Search vendor "Cvs" for product "Cvs" and version "1.11.15" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.16 Search vendor "Cvs" for product "Cvs" and version "1.11.16" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.1 Search vendor "Cvs" for product "Cvs" and version "1.12.1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.2 Search vendor "Cvs" for product "Cvs" and version "1.12.2" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.5 Search vendor "Cvs" for product "Cvs" and version "1.12.5" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.7 Search vendor "Cvs" for product "Cvs" and version "1.12.7" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.8 Search vendor "Cvs" for product "Cvs" and version "1.12.8" | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | * | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | 1.3 Search vendor "Openpkg" for product "Openpkg" and version "1.3" | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | 2.0 Search vendor "Openpkg" for product "Openpkg" and version "2.0" | - |
Affected
| ||||||
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 2.4 Search vendor "Sgi" for product "Propack" and version "2.4" | - |
Affected
| ||||||
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 3.0 Search vendor "Sgi" for product "Propack" and version "3.0" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Linux Search vendor "Gentoo" for product "Linux" | 1.4 Search vendor "Gentoo" for product "Linux" and version "1.4" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | * | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.4 Search vendor "Openbsd" for product "Openbsd" and version "3.4" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.5 Search vendor "Openbsd" for product "Openbsd" and version "3.5" | - |
Affected
|