7.5

CVE-2004-1082

mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.

Data is provided by the National Vulnerability Database (NVD)
ApacheHTTP Server Version1.3
ApacheHTTP Server Version1.3.1
ApacheHTTP Server Version1.3.3
ApacheHTTP Server Version1.3.4
ApacheHTTP Server Version1.3.6
ApacheHTTP Server Version1.3.7 Editiondev
ApacheHTTP Server Version1.3.9
ApacheHTTP Server Version1.3.11
ApacheHTTP Server Version1.3.12
ApacheHTTP Server Version1.3.14
ApacheHTTP Server Version1.3.17
ApacheHTTP Server Version1.3.18
ApacheHTTP Server Version1.3.19
ApacheHTTP Server Version1.3.20
ApacheHTTP Server Version1.3.22
ApacheHTTP Server Version1.3.23
ApacheHTTP Server Version1.3.24
ApacheHTTP Server Version1.3.25
ApacheHTTP Server Version1.3.26
ApacheHTTP Server Version1.3.27
ApacheHTTP Server Version1.3.28
ApacheHTTP Server Version1.3.29
AvayaCommunication Manager Version1.1
AvayaCommunication Manager Version1.3.1
AvayaCommunication Manager Version2.0
AvayaCommunication Manager Version2.0.1
HpVirtualvault Version4.5
HpVirtualvault Version4.6
HpVirtualvault Version4.7
HpWebproxy Versiona.02.00
HpWebproxy Versiona.02.10
IbmHTTP Server Version1.3.19
AvayaMn100
OpenbsdOpenbsd Version3.4
OpenbsdOpenbsd Version3.5
OpenbsdOpenbsd Versioncurrent
ScoOpenserver Version5.0.6
ScoOpenserver Version5.0.7
SunSolaris Version8.0 Editionx86
SunSolaris Version9.0 Editionsparc
SunSolaris Version9.0 Editionx86
SunSunos Version5.8
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.47% 0.898
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P