VDB
CVE-2004-0430
CVE-2004-0430
PUBLISHED
CVSS 5.099999904632568 MEDIUM
Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.
EPSS 41.30% · 98.7th percentile
Risk Scores
CVSS 2.0
5.099999904632568
EPSS Score
41.30%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| apple | mac_os_x_server | 0 |
| n/a | n/a | n/a |
| apple | mac_os_x | 0 |
Timeline
- May 6, 2004 CVE Published
- Sep 20, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 19, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 13, 2023 EPSS Score
- May 26, 2023 EPSS Score
References
- APPLE-SA-2004-05-03 vendor-advisory
- 11539 third-party-advisory
- http://securitytracker.com/id?1010039 technical
- http://www.atstake.com/research/advisories/2004/a050304-1.txt patch
- http://www.kb.cert.org/vuls/id/648406 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2004-0430 advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16049 url
- http://www.securiteam.com/securitynews/5QP0115CUO.html url