Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2004-0179Use of Externally-Controlled Format String in Neon

Severity
6.8MEDIUMNVD
EPSS
8.1%
top 7.80%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 1
Latest updateMay 3

Description

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

CVSS vector

AV:N/AC:M/C:P/I:P/A:PExploitability: 8.6 | Impact: 6.4

Affected Packages1 packages

NVDwebdav/neon0.19.00.24.5

Also affects: Debian Linux 3.0

🔴Vulnerability Details

1
GHSA
GHSA-3265-7c8c-jh75: Multiple format string vulnerabilities in (1) neon 02022-05-03

💥Exploits & PoCs

1
Exploit-DB
Neon WebDAV Client Library 0.2x - Format String2004-04-14

📋Vendor Advisories

1
Red Hat
security flaw2004-04-14

💬Community

1
Bugzilla
CVE-2004-0179 security flaw2018-08-16