CVE-2004-0369
Last modified
CVE-2004-0369 is a vulnerability of currently unknown severity. Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.. EPSS estimates a 4.37% chance of exploitation in the next 30 days.
Description
Buffer overflow in Entrust LibKmp ISAKMP library, as used by Symantec Enterprise Firewall 7.0 through 8.0, Gateway Security 5300 1.0, Gateway Security 5400 2.0, and VelociRaptor 1.5, allows remote attackers to execute arbitrary code via a crafted ISAKMP payload.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Entrust | Entrust Libkmp Isakmp Library | All versions |
| Symantec | Enterprise Firewall | 7.0 |
| Symantec | Enterprise Firewall | 7.0.4 |
| Symantec | Enterprise Firewall | 8.0 |
| Symantec | Velociraptor | 1.5 |
| Symantec | Gateway Security 5300 | 1.0 |
| Symantec | Gateway Security 5400 | 2.0 |
References
- http://www.auscert.org.au/render.html?it=4339Vendor Advisory
- http://www.ciac.org/ciac/bulletins/o-206.shtmlVendor Advisory
- http://xforce.iss.net/xforce/alerts/id/181Patch, Vendor Advisory
- http://www.auscert.org.au/render.html?it=4339Vendor Advisory
- http://www.ciac.org/ciac/bulletins/o-206.shtmlVendor Advisory
- http://xforce.iss.net/xforce/alerts/id/181Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0369?
How severe is CVE-2004-0369?
How do I fix CVE-2004-0369?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0363Stack-based buffer overflow in the SymSpamHelper ActiveX com…
- CVE-2004-0364The WrapNISUM ActiveX component (WrapUM.dll) in Norton Inter…
- CVE-2004-0365The dissect_attribute_value_pairs function in packet-radius.…7.5
- CVE-2004-0366SQL injection vulnerability in the libpam-pgsql library befo…
- CVE-2004-0367Ethereal 0.10.1 to 0.10.2 allows remote attackers to cause a…
- CVE-2004-0368Double free vulnerability in dtlogin in CDE on Solaris, HP-U…
- CVE-2004-0370The setsockopt call in the KAME Project IPv6 implementation,…
- CVE-2004-0371Heimdal 0.6.x before 0.6.1 and 0.5.x before 0.5.3 does not p…
- CVE-2004-0372xine allows local users to overwrite arbitrary files via a s…
- CVE-2004-0374Interchange before 5.0.1 allows remote attackers to "expose …
- CVE-2004-0375SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 20…
- CVE-2004-0376oftpd 0.3.6 and earlier allows remote attackers to cause a d…
Are you affected by CVE-2004-0369?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
