WebDAV neon 0.24.4

CPE Details

WebDAV neon 0.24.4
0.24.4
2020-05-26
13h02 +00:00
2020-05-26
13h02 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:webdav:neon:0.24.4:*:*:*:*:*:*:*

Informations

Vendor

webdav

Product

neon

Version

0.24.4

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2009-2474 2009-08-21 15h00 +00:00 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.
5.8
CVE-2004-0398 2004-05-20 02h00 +00:00 Heap-based buffer overflow in the ne_rfc1036_parse date parsing function for the neon library (libneon) 0.24.5 and earlier, as used by cadaver before 0.22, allows remote WebDAV servers to execute arbitrary code on the client.
7.5
CVE-2004-0179 2004-04-16 02h00 +00:00 Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
6.8