Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-0883

EPSS 15.37% · P95
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2004-0883

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple vulnerabilities in the samba filesystem (smbfs) in Linux kernel 2.4 and 2.6 allow remote samba servers to cause a denial of service (crash) or gain sensitive information from kernel memory via a samba server (1) returning more data than requested to the smb_proc_read function, (2) returning a data offset from outside the samba packet to the smb_proc_readX function, (3) sending a certain TRANS2 fragmented packet to the smb_receive_trans2 function, (4) sending a samba packet with a certain header size to the smb_proc_readX_data function, or (5) sending a certain packet based offset for the data in a packet to the smb_receive_trans2 function.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Linux smbfs 多个 远程拒绝服务漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Linux Kernel smbfs是Linux内核支持的文件系统,用于共享应用。 Linux Kernel 2.4及2.6中的smbfs存在多个漏洞,可导致拒绝服务或信息泄露。 远程samba服务器可通过多种方式实施攻击,包括(1)返回远超过所请求的数据给smb_proc_read函数;(2)返回一个包含offset的samba包给smb_proc_readX函数;(3)发送一个特殊构造的TRANS2碎片包给smb_receive_trans2函数(4) 发送一个包含特殊头长度信息的samba包给smb
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2004-0883

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2004-0883

Please Login to view more intelligence information

Same Patch Batch · n/a · 2004-12-01 · 46 CVEs total

CVE-2004-1108Gentoo Gentoolkit 文件覆盖漏洞
CVE-2004-1111Cisco IOS DHCP 拒绝服务漏洞
CVE-2004-1113SQLgreyPostfixGreylistingService email地址 SQL注入漏洞
CVE-2004-1116mersenne.org GIMPS 本地权限提升漏洞
CVE-2004-1117chessbrain.net ChessBrain init 用户权限提升漏洞
CVE-2004-1118weonlydo WodFTPDLX WodFTPDLX.dll 缓冲区溢出漏洞
CVE-2004-1119Winamp in_cdda.dll 缓冲区溢出漏洞
CVE-2004-1120ProZilla 多个 缓冲区溢出漏洞
CVE-2004-1115Berkeley SETI@home 本地权限提升漏洞
CVE-2004-1109Kerio PersonalFirewall FWDRV.SYS 拒绝服务漏洞
CVE-2004-1110MtinkStatusMonitor epso 文件覆盖漏洞
CVE-2004-1107Gentoo Portage dispatch-conf 文件覆盖漏洞
CVE-2004-1106Gallery index.php 跨站脚本攻击漏洞
CVE-2004-1105Noterl ContivityVPNClient ErrorMessage 信息泄露漏洞
CVE-2004-1104Microsoft Internet Explorer HTML格式标签URI模糊漏洞
CVE-2004-1103Mcenter MailPost debug 信息泄露漏洞
CVE-2004-1102Mcenter MailPost ErrorMessage 信息泄露漏洞
CVE-2004-1101Mcenter MailPost mailpost.exe 多种安全漏洞
CVE-2004-1100mcenter MailPost mailpost.exe 跨站脚本攻击漏洞
CVE-2004-1099Cisco ACS 绕过身份认证漏洞

Showing top 20 of 46 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2004-0883

No comments yet


Leave a comment