CVE-2004-0826

3 documents3 sources
Severity
7.5HIGH
EPSS
3.0%
top 13.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 31
Latest updateApr 29

Description

Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record length field in an SSLv2 client hello message.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages9 packages

NVDnetscape/directory_server6 versions+5
NVDnetscape/enterprise_server19 versions+18
NVDhp/hp-ux11.00, 11.11, 11.23+2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-v2jq-g922-rhj4: Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record2022-04-29
CVEList
CVE-2004-0826: Heap-based buffer overflow in Netscape Network Security Services (NSS) library allows remote attackers to execute arbitrary code via a modified record2004-09-02
CVE-2004-0826 (HIGH CVSS 7.5) | Heap-based buffer overflow in Netsc | cvebase.io