VDB

CVE-2004-0492

CVE-2004-0492 PUBLISHED CVSS 10 CRITICAL

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

EPSS 23.71% · 96.1th percentile

Risk Scores

CVSS 2.0
10
EPSS Score
23.71%
96.1th percentile

Affected Products

VendorProductVersions
hpwebproxy2.1, 2.0
apachehttp_server1.3.31, 1.3.29, 1.3.27
ibmhttp_server1.3.26.2, 1.3.26, 1.3.26.1
sgipropack2.4
n/an/an/a
openbsdopenbsd3.4, 3.5
hpvirtualvault11.0.4
hpvvos11.04

Timeline

  • Jun 23, 2004 CVE Published
  • Sep 23, 2010 PoC Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 9, 2023 EPSS Score
  • Apr 3, 2023 EPSS Score
  • May 25, 2023 EPSS Score
  • Sep 8, 2023 EPSS Score
  • Oct 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›