VDB
CVE-2004-0398
CVE-2004-0398
PUBLISHED
CVSS 7.5 HIGH
Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
EPSS 5.01% · 91.4th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
5.01%
91.4th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| webdav | cadaver | 0 |
| debian | debian_linux | 3.0 |
| webdav | neon | 0 |
Timeline
- May 20, 2004 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- 11650 third-party-advisory
- GLSA-200405-15 vendor-advisory
- 10385 vdb
- DSA-506 vendor-advisory
- FEDORA-2004-1552 vendor-advisory
- neon-library-nerfc1036parse-bo(16192) vdb
- DSA-507 vendor-advisory
- 20040519 [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon) mailing-list
- 20040519 Advisory 06/2004: libneon date parsing vulnerability mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2004-0398 advisory
- http://secunia.com/advisories/11673 url
- http://www.ciac.org/ciac/bulletins/o-148.shtml url
- http://archives.neohapsis.com/archives/fulldisclosure/2004-05/0982.html technical
- http://www.mandriva.com/security/advisories?name=MDKSA-2004:049 advisory
- http://www.osvdb.org/6302 technical
- http://www.redhat.com/support/errata/RHSA-2004-191.html advisory
- http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000841 technical
- http://secunia.com/advisories/11638 advisory
- http://security.gentoo.org/glsa/glsa-200405-13.xml advisory