6.4

CVE-2004-0235

Exploit

Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").

Data is provided by the National Vulnerability Database (NVD)
ClearswiftMailsweeper Version4.0
ClearswiftMailsweeper Version4.1
ClearswiftMailsweeper Version4.2
ClearswiftMailsweeper Version4.3
ClearswiftMailsweeper Version4.3.3
ClearswiftMailsweeper Version4.3.4
ClearswiftMailsweeper Version4.3.5
ClearswiftMailsweeper Version4.3.6
ClearswiftMailsweeper Version4.3.6_sp1
ClearswiftMailsweeper Version4.3.7
ClearswiftMailsweeper Version4.3.8
ClearswiftMailsweeper Version4.3.10
ClearswiftMailsweeper Version4.3.11
ClearswiftMailsweeper Version4.3.13
F-secureF-secure Anti-virus Version4.51 Editionlinux_gateways
F-secureF-secure Anti-virus Version4.51 Editionlinux_servers
F-secureF-secure Anti-virus Version4.51 Editionlinux_workstations
F-secureF-secure Anti-virus Version4.52 Editionlinux_gateways
F-secureF-secure Anti-virus Version4.52 Editionlinux_servers
F-secureF-secure Anti-virus Version4.52 Editionlinux_workstations
F-secureF-secure Anti-virus Version4.60 Editionsamba_servers
F-secureF-secure Anti-virus Version5.5 Editionclient_security
F-secureF-secure Anti-virus Version5.41 Editionmimesweeper
F-secureF-secure Anti-virus Version5.41 Editionwindows_servers
F-secureF-secure Anti-virus Version5.41 Editionworkstations
F-secureF-secure Anti-virus Version5.42 Editionmimesweeper
F-secureF-secure Anti-virus Version5.42 Editionwindows_servers
F-secureF-secure Anti-virus Version5.42 Editionworkstations
F-secureF-secure Anti-virus Version5.52 Editionclient_security
F-secureF-secure Anti-virus Version6.21 Editionms_exchange
F-secureF-secure Anti-virus Version2003
F-secureF-secure Anti-virus Version2004
F-secureInternet Gatekeeper Version6.31
F-secureInternet Gatekeeper Version6.32
RARLABWinRAR Version3.20
RedhatLha Version1.14i-9 Editioni386
SgiPropack Version2.4
SgiPropack Version3.0
StalkerCgpmcafee Version3.2
Tsugio OkamotoLha Version1.14
Tsugio OkamotoLha Version1.15
Tsugio OkamotoLha Version1.17
WinzipWinzip Version9.0
RedhatFedora Core Versioncore_1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 6.96% 0.906
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:P/A:N