7.5

CVE-2004-0193

Heap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Proventia A, G, and M Series, RealSecure Desktop 7.0 and 3.6, RealSecure Guard 3.6, RealSecure Sentry 3.6, BlackICE PC Protection 3.6, and BlackICE Server Protection 3.6, allows remote attackers to execute arbitrary code via an SMB packet containing an authentication request with a long username.

Data is provided by the National Vulnerability Database (NVD)
IssBlackice Agent Server Version3.6eca
IssBlackice Pc Protection Version3.6cbd
IssBlackice Server Protection Version3.6cbz
IssRealsecure Desktop Version3.6eca
IssRealsecure Desktop Version3.6ecf
IssRealsecure Desktop Version7.0ebg
IssRealsecure Desktop Version7.0epk
IssRealsecure Guard Version3.6ecb
IssRealsecure Network Version7.0 Updatexpu_20.15
IssRealsecure Sentry Version3.6ecf
IssRealsecure Server Sensor Version7.0 Updatexpu20.16
IssProventia A Series Xpu Version20.15
IssProventia G Series Xpu Version22.3
IssProventia M Series Xpu Version1.30
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 28.45% 0.963
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P