Multiple format string vulnerabilities in (1) neon 0.24.4 and earlier, and other products that use neon including (2) Cadaver, (3) Subversion, and (4) OpenOffice, allow remote malicious WebDAV servers to execute arbitrary code.
2004-06-01T04:00:00.000
2025-04-03T01:03:51.193
Deferred
CVSSv2: 6.8 (MEDIUM)
AV:N/AC:M/Au:N/C:P/I:P/A:P
8.6
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | webdav | neon | < 0.24.5 | Yes |
Application | apache | openoffice | * | No |
Application | apache | subversion | * | No |
Application | webdav | cadaver | * | No |
Operating System | debian | debian_linux | 3.0 | Yes |