peter bassill · operator
$ cve CVE-2004-0362 JSON

CVE-2004-0362 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 73.3% (pctl 99)

Patch early

A public exploit exists.

Description

Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS73.33% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2004-04-15
Last modified2026-06-16

Affected (11)

VendorProduct
issblackice agent server
issblackice pc protection
issblackice server protection
issproventia a series xpu
issproventia g series xpu
issproventia m series xpu
issrealsecure desktop
issrealsecure guard
issrealsecure network sensor
issrealsecure sentry
issrealsecure server sensor

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD