CVE-2004-0418
092004.txt
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.
serve_notify en CVS 1.12.x a 1.12.8 y 1.11.x a 1.11.16 no maneja adecuadamente líneas de datos vacías, lo que puede permitir a atacantes remotos realizar una escritura "fuera de límites" en un solo byte para ejecutar código arbitrario o modificar datos críticos del programa.
A team audit of the CVS codebase has revealed more security related problems. The vulnerabilities discovered include exploitable, potentially exploitable and simple crash bugs. Vulnerable versions are CVS feature releases up to 1.12.8 and stable release up to 1.11.16.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2004-04-16 CVE Reserved
- 2004-06-10 CVE Published
- 2024-08-08 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (13)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.debian.org/security/2004/dsa-519 | 2018-05-03 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.10.7 Search vendor "Cvs" for product "Cvs" and version "1.10.7" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.10.8 Search vendor "Cvs" for product "Cvs" and version "1.10.8" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11 Search vendor "Cvs" for product "Cvs" and version "1.11" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.1 Search vendor "Cvs" for product "Cvs" and version "1.11.1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.1_p1 Search vendor "Cvs" for product "Cvs" and version "1.11.1_p1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.2 Search vendor "Cvs" for product "Cvs" and version "1.11.2" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.3 Search vendor "Cvs" for product "Cvs" and version "1.11.3" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.4 Search vendor "Cvs" for product "Cvs" and version "1.11.4" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.5 Search vendor "Cvs" for product "Cvs" and version "1.11.5" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.6 Search vendor "Cvs" for product "Cvs" and version "1.11.6" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.10 Search vendor "Cvs" for product "Cvs" and version "1.11.10" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.11 Search vendor "Cvs" for product "Cvs" and version "1.11.11" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.14 Search vendor "Cvs" for product "Cvs" and version "1.11.14" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.15 Search vendor "Cvs" for product "Cvs" and version "1.11.15" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.11.16 Search vendor "Cvs" for product "Cvs" and version "1.11.16" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.1 Search vendor "Cvs" for product "Cvs" and version "1.12.1" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.2 Search vendor "Cvs" for product "Cvs" and version "1.12.2" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.5 Search vendor "Cvs" for product "Cvs" and version "1.12.5" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.7 Search vendor "Cvs" for product "Cvs" and version "1.12.7" | - |
Affected
| ||||||
Cvs Search vendor "Cvs" | Cvs Search vendor "Cvs" for product "Cvs" | 1.12.8 Search vendor "Cvs" for product "Cvs" and version "1.12.8" | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | * | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | 1.3 Search vendor "Openpkg" for product "Openpkg" and version "1.3" | - |
Affected
| ||||||
Openpkg Search vendor "Openpkg" | Openpkg Search vendor "Openpkg" for product "Openpkg" | 2.0 Search vendor "Openpkg" for product "Openpkg" and version "2.0" | - |
Affected
| ||||||
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 2.4 Search vendor "Sgi" for product "Propack" and version "2.4" | - |
Affected
| ||||||
Sgi Search vendor "Sgi" | Propack Search vendor "Sgi" for product "Propack" | 3.0 Search vendor "Sgi" for product "Propack" and version "3.0" | - |
Affected
| ||||||
Gentoo Search vendor "Gentoo" | Linux Search vendor "Gentoo" for product "Linux" | 1.4 Search vendor "Gentoo" for product "Linux" and version "1.4" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | * | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.4 Search vendor "Openbsd" for product "Openbsd" and version "3.4" | - |
Affected
| ||||||
Openbsd Search vendor "Openbsd" | Openbsd Search vendor "Openbsd" for product "Openbsd" | 3.5 Search vendor "Openbsd" for product "Openbsd" and version "3.5" | - |
Affected
|