VDB

CVE-2004-0362

CVE-2004-0362 PUBLISHED CVSS 7.5 HIGH

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

EPSS 83.40% · 99.3th percentile

Risk Scores

CVSS 2.0
7.5
EPSS Score
83.40%
99.3th percentile

Affected Products

VendorProductVersions
issproventia_g_series_xpu22.2, 22.3, 22.4
issblackice_server_protection3.6ccc, *, 3.6cca
issproventia_a_series_xpu22.7, 22.4, 20.11
issproventia_m_series_xpu1.9, 1.7, 1.6
issblackice_pc_protection3.6cca, 3.6cce, 3.6ccf
issrealsecure_sentry*, *, *
issrealsecure_desktop7.0ebf, 7.0eba, 3.6ecf
issrealsecure_network_sensor7.0, 7.0, 7.0
issblackice_agent_server*, 3.6ebz, 3.6eca
n/an/an/a
issrealsecure_guard3.6ecb, 3.6eca, 3.6ebz
issrealsecure_server_sensor6.5_win_sr3.10, 6.5_win_sr3.7, 6.5_win_sr3.5

Timeline

  • Mar 18, 2004 CVE Published
  • Sep 20, 2010 PoC Published
  • May 29, 2018 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›