CVE-2004-0940
HIGHApache <1.3.32 - Buffer Overflow
Title source: llmDescription
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI documents to execute arbitrary code as the apache user via SSI (XSSI) documents that trigger a length calculation error.
Exploits (2)
References (21)
... and 1 more
Scores
CVSS v3
7.8
EPSS
0.0368
EPSS Percentile
88.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-131
Status
published
Products (21)
apache/http_server
1.3 - 1.3.32
hp/hp-ux
11.00
hp/hp-ux
11.11
hp/hp-ux
11.20
hp/hp-ux
11.22
openpkg/openpkg
2.0
openpkg/openpkg
2.1
openpkg/openpkg
2.2
slackware/slackware_linux
8.0
slackware/slackware_linux
8.1
... and 11 more
Published
Feb 09, 2005
Tracked Since
Feb 18, 2026