← Back to CVE List
Vulnerability Intelligence Report

CVE-2004-0418

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

No Active Exploit Signals
CVSS Base Score
10.0
HIGH
EPSS Probability:5.68%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Affected Products & Versions

Vendor Product Affected Versions
cvs cvs 1.10.7, 1.10.8, 1.11, 1.11.1, 1.11.1_p1, 1.11.2, 1.11.3, 1.11.4, 1.11.5, 1.11.6, 1.11.10, 1.11.11, 1.11.14, 1.11.15, 1.11.16, 1.12.1, 1.12.2, 1.12.5, 1.12.7, 1.12.8
openpkg openpkg 1.3, 2.0
sgi propack 2.4, 3.0
gentoo linux 1.4
openbsd openbsd 3.4, 3.5

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
5.681%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2004-04-16T00:00:00
Published2004-06-11T04:00:00
Patch Date2004-06-09
Last Updated2024-08-08T00:17:14

LINK COPIED TO CLIPBOARD