← Back

CVE-2004-0362

nvd nist
Published: Apr 15, 2004Modified: Apr 16, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

Affected (109)

11 products
Blackice Agent Server
Blackice Pc Protection
Blackice Server Protection
Realsecure Desktop
Realsecure Guard
Realsecure Network Sensor
Realsecure Sentry
Realsecure Server Sensor
Proventia A Series Xpu
Proventia G Series Xpu
Proventia M Series Xpu
Configuration A
78 vulnerable
Vulnerable SoftwareAffected Versions
Iss
Version 3.6ebz
Version 3.6eca
Version 3.6ecb
Version 3.6ecc
Version 3.6ecd
Version 3.6ece
Version 3.6ecf
Iss
Version 3.6cbz
Version 3.6cca
Version 3.6ccb
Version 3.6ccc
Version 3.6ccd
Version 3.6cce
Version 3.6ccf
Iss
Version 3.6cbz
Version 3.6cca
Version 3.6ccb
Version 3.6ccc
Version 3.6ccd
Version 3.6cce
Version 3.6ccf
Iss
Version 3.6ebz
Version 3.6eca
Version 3.6ecb
Version 3.6ecd
Version 3.6ece
Version 3.6ecf
Version 7.0eba
Version 7.0ebf
Version 7.0ebg
Version 7.0ebh
Version 7.0ebj
Version 7.0ebk
Version 7.0ebl
Iss
Version 3.6ebz
Version 3.6eca
Version 3.6ecb
Version 3.6ecc
Version 3.6ecd
Version 3.6ece
Version 3.6ecf
Iss
Version 7.0
Version 7.0 xpu_20.11
Version 7.0 xpu_22.10
Version 7.0 xpu_22.4
Version 7.0 xpu_22.9
Iss
Version 3.6ebz
Version 3.6eca
Version 3.6ecb
Version 3.6ecc
Version 3.6ecd
Version 3.6ece
Version 3.6ecf
Iss
Version 6.0.1
Version 6.0.1_win_sr1.1
Version 6.0
Version 6.5
Version 6.5 sr3.2
Version 6.5 sr3.3
Version 6.5_win_sr3.10
Version 6.5_win_sr3.1
Version 6.5_win_sr3.4
Version 6.5_win_sr3.5
Version 6.5_win_sr3.6
Version 6.5_win_sr3.7
Version 6.5_win_sr3.8
Version 6.5_win_sr3.9
Version 7.0 xpu22.10
Version 7.0 xpu22.11
Version 7.0 xpu22.1
Version 7.0 xpu22.2
Version 7.0 xpu22.3
Version 7.0 xpu22.4
Version 7.0 xpu22.5
Version 7.0 xpu22.6
Version 7.0 xpu22.7
Version 7.0 xpu22.8
Version 7.0 xpu22.9
Configuration B
31 vulnerable

References (20)

Source: cve@mitre.org
PatchThird Party AdvisoryUS Government Resource
Source: cve@mitre.org
Source: cve@mitre.org
ExploitPatchVendor Advisory
Source: cve@mitre.org
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.