CVE-2004-0398 is a heap-based buffer overflow vulnerability in the neon library (libneon) versions 0.24.5 and earlier, specifically within the ne_rfc1036_parse date parsing function. This flaw, affecting products like cadaver, allows remote WebDAV servers to execute arbitrary code on client systems. With a CVSS score of 7.5, it represents a high-severity risk, enabling remote attackers to achieve partial confidentiality, integrity, and availability impacts with low attack complexity and no authentication required. Despite its age and severity, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.22.0CPE matchmatch criteria | cpe:2.3:a:webdav:cadaver:*:*:*:*:*:*:*:* | ||
<= 0.24.5CPE matchmatch criteria | cpe:2.3:a:webdav:neon:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.