10

CVE-2004-0414

CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being used and may lead to a denial of service (crash), modification of critical program data, or arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
CvsCvs Version1.10.7
CvsCvs Version1.10.8
CvsCvs Version1.11
CvsCvs Version1.11.1
CvsCvs Version1.11.1_p1
CvsCvs Version1.11.2
CvsCvs Version1.11.3
CvsCvs Version1.11.4
CvsCvs Version1.11.5
CvsCvs Version1.11.6
CvsCvs Version1.11.10
CvsCvs Version1.11.11
CvsCvs Version1.11.14
CvsCvs Version1.11.15
CvsCvs Version1.11.16
CvsCvs Version1.12.1
CvsCvs Version1.12.2
CvsCvs Version1.12.5
CvsCvs Version1.12.7
CvsCvs Version1.12.8
OpenpkgOpenpkg Version1.3
OpenpkgOpenpkg Version2.0
SgiPropack Version2.4
SgiPropack Version3.0
GentooLinux Version1.4
OpenbsdOpenbsd Version3.4
OpenbsdOpenbsd Version3.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.25% 0.896
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C