CVE-2004-0492 PUBLISHED CVSS 10 CRITICAL

Heap-based buffer overflow in proxy_util.c for mod_proxy in Apache 1.3.25 to 1.3.31 allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a negative Content-Length HTTP header field, which causes a large amount of data to be copied.

EPSS 23.71% · 95.9th percentile

Risk Scores

CVSS v2.0
10
EPSS Score
23.71%
95.9th percentile

Affected Products

VendorProductVersions
hpwebproxy2.0, 2.1
apachehttp_server1.3.27, 1.3.29, 1.3.31
ibmhttp_server1.3.28, 1.3.26.2, 1.3.26
sgipropack2.4
n/an/an/a
openbsdopenbsd3.4, 3.5
hpvirtualvault11.0.4
hpvvos11.04

Timeline

References

…and 12 more

Open in Interactive Console →