peter bassill · operator
$ cve CVE-2004-0179 JSON

CVE-2004-0179 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 11.1% (pctl 96)

Patch early

A public exploit exists.

Description

Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS11.06% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2004-06-01
Last modified2026-06-16

Affected (5)

VendorProduct
apacheopenoffice
apachesubversion
debiandebian linux
webdavcadaver
webdavneon

Public exploits

SourceTitleDate
exploit-dbNeon WebDAV Client Library 0.2x - Format String2004-04-14

References

→ the Explorer  ·  watch your stack  ·  NVD