CyberSec.Space Logo
Back to CVE Browser

CVE-2004-0418

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1420%
EPSS Percentile41.45th
PublishedAug 6, 2004
Last ModifiedApr 16, 2026

Vulnerability Description

serve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to perform an "out-of-bounds" write for a single byte to execute arbitrary code or modify critical program data.

Affected Platforms (CPE)

πŸ“¦
Cvs

Cvs

= 1.10.7
πŸ“¦
Cvs

Cvs

= 1.10.8
πŸ“¦
Cvs

Cvs

= 1.11
πŸ“¦
Cvs

Cvs

= 1.11.1
πŸ“¦
Cvs

Cvs

= 1.11.1_p1
πŸ“¦
Cvs

Cvs

= 1.11.2
πŸ“¦
Cvs

Cvs

= 1.11.3
πŸ“¦
Cvs

Cvs

= 1.11.4
πŸ“¦
Cvs

Cvs

= 1.11.5
πŸ“¦
Cvs

Cvs

= 1.11.6
πŸ“¦
Cvs

Cvs

= 1.11.10
πŸ“¦
Cvs

Cvs

= 1.11.11
πŸ“¦
Cvs

Cvs

= 1.11.14
πŸ“¦
Cvs

Cvs

= 1.11.15
πŸ“¦
Cvs

Cvs

= 1.11.16
πŸ“¦
Cvs

Cvs

= 1.12.1
πŸ“¦
Cvs

Cvs

= 1.12.2
πŸ“¦
Cvs

Cvs

= 1.12.5
πŸ“¦
Cvs

Cvs

= 1.12.7
πŸ“¦
Cvs

Cvs

= 1.12.8
πŸ“¦
Openpkg

Openpkg

All versions
πŸ“¦
Openpkg

Openpkg

= 1.3
πŸ“¦
Openpkg

Openpkg

= 2.0
πŸ“¦
Sgi

Propack

= 2.4
πŸ“¦
Sgi

Propack

= 3.0
πŸ’»
Gentoo

Linux

= 1.4
πŸ’»
Openbsd

Openbsd

All versions
πŸ’»
Openbsd

Openbsd

= 3.4
πŸ’»
Openbsd

Openbsd

= 3.5

References & Advisories

Related Vulnerabilities