CVE-2004-0362 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 73.3% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the ICQ parsing routines of the ISS Protocol Analysis Module (PAM) component, as used in various RealSecure, Proventia, and BlackICE products, allow remote attackers to execute arbitrary code via a SRV_MULTI response containing a SRV_USER_ONLINE response packet and a SRV_META_USER response packet with long (1) nickname, (2) firstname, (3) lastname, or (4) email address fields, as exploited by the Witty worm.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 73.33% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2004-04-15 |
| Last modified | 2026-06-16 |
Affected (11)
| Vendor | Product |
|---|---|
| iss | blackice agent server |
| iss | blackice pc protection |
| iss | blackice server protection |
| iss | proventia a series xpu |
| iss | proventia g series xpu |
| iss | proventia m series xpu |
| iss | realsecure desktop |
| iss | realsecure guard |
| iss | realsecure network sensor |
| iss | realsecure sentry |
| iss | realsecure server sensor |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ISS - 'PAM.dll' ICQ Parser Buffer Overflow (Metasploit) | 2010-09-20 |
| exploit-db | RealSecure / Blackice - 'iss_pam1.dll' Remote Overflow | 2004-03-28 |
References
- http://marc.info/?l=bugtraq&m=107965651712378&w=2
- http://secunia.com/advisories/11073
- http://www.ciac.org/ciac/bulletins/o-104.shtml
- http://www.eeye.com/html/Research/Advisories/AD20040318.html
- http://www.kb.cert.org/vuls/id/947254
- http://www.osvdb.org/4355
- http://www.securityfocus.com/bid/9913
- http://xforce.iss.net/xforce/alerts/id/166
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15442
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15543
- http://marc.info/?l=bugtraq&m=107965651712378&w=2
- http://secunia.com/advisories/11073
- http://www.ciac.org/ciac/bulletins/o-104.shtml
- http://www.eeye.com/html/Research/Advisories/AD20040318.html
- http://www.kb.cert.org/vuls/id/947254
- http://www.osvdb.org/4355
- http://www.securityfocus.com/bid/9913
- http://xforce.iss.net/xforce/alerts/id/166
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15442
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15543
→ the Explorer · watch your stack · NVD