Vulnerability Name: | CVE-2004-0897 (CCN-18758) | ||||||||||||
Assigned: | 2004-09-22 | ||||||||||||
Published: | 2005-01-11 | ||||||||||||
Updated: | 2018-10-12 | ||||||||||||
Summary: | The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack. | ||||||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2004-0897 Source: CCN Type: SA13802 Microsoft Windows Indexing Service Buffer Overflow Vulnerability Source: SECUNIA Type: UNKNOWN 13802 Source: CCN Type: SECTRACK ID: 1012833 Windows Indexing Service Buffer Overflow in Processing Queries Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: UNKNOWN 1012833 Source: CCN Type: Avaya Security Advisory ASA-2005-004 Windows Security Updates for December 2004 - (MS05-001 - MS05-003) Source: CCN Type: CIAC Information Bulletin P-095 Microsoft Vulnerability in the Indexing Service Source: CIAC Type: Vendor Advisory P-095 Source: CCN Type: US-CERT VU#657118 Microsoft Windows Indexing Service fails to properly handle query validation Source: CERT-VN Type: Patch, Third Party Advisory, US Government Resource VU#657118 Source: CCN Type: Microsoft Security Bulletin MS05-003 Vulnerability in the Indexing Service Could Allow Remote Code Execution (871250) Source: CCN Type: Microsoft Security Bulletin MS06-053 Vulnerability in Indexing Service Could Allow Cross-Site Scripting (920685) Source: CCN Type: Microsoft Security Bulletin MS09-057 Vulnerability in Indexing Service Could Allow Remote Code Execution (969059) Source: BID Type: UNKNOWN 12228 Source: CCN Type: BID-12228 Microsoft Windows Indexing Service Buffer Overflow Vulnerability Source: MS Type: UNKNOWN MS05-003 Source: XF Type: UNKNOWN win-indexing-code-execution(18758) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2128 Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:2447 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |