Vulnerability Intelligence Report
CVE-2004-0414
CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.
No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:3.97%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| cvs | cvs | 1.10.7, 1.10.8, 1.11, 1.11.1, 1.11.1_p1, 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6, 1.11.10, 1.11.11, 1.11.14, 1.11.15, 1.11.16, 1.12.1, 1.12.2, 1.12.5, 1.12.7, 1.12.8 |
| openpkg | openpkg | 1.3, 2.0 |
| sgi | propack | 2.4, 3.0 |
| gentoo | linux | 1.4 |
| openbsd | openbsd | 3.4, 3.5 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.969%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2004-04-16T00:00:00 |
| Published | 2004-06-11T04:00:00 |
| Patch Date | 2004-06-09 |
| Last Updated | 2024-08-08T00:17:14 |
Community Chatter & Buzz