CVE-2004-0552
Last modified
CVE-2004-0552 is a vulnerability of currently unknown severity. Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.. EPSS estimates a 23.87% chance of exploitation in the next 30 days.
Description
Sophos Small Business Suite 1.00 on Windows does not properly handle files whose names contain reserved MS-DOS device names such as (1) LPT1, (2) COM1, (3) AUX, (4) CON, or (5) PRN, which can allow malicious code to bypass detection when it is installed, copied, or executed.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sophos | Small Business Suite | <= 1.00 |
References
- http://www.seifried.org/security/advisories/kssa-005.htmlExploit, Patch, Vendor Advisory
- http://www.seifried.org/security/advisories/kssa-005.htmlExploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2004-0552?
How severe is CVE-2004-0552?
How do I fix CVE-2004-0552?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2004
- CVE-2004-0545LVM for AIX 5.1 and 5.2 allows local users to overwrite arbi…
- CVE-2004-0547Buffer overflow in the ODBC driver for PostgreSQL before 7.2…
- CVE-2004-0548Multiple stack-based buffer overflows in the word-list-compr…
- CVE-2004-0549The WebBrowser ActiveX control, or the Internet Explorer HTM…
- CVE-2004-0550Buffer overflow in Real Networks RealPlayer 10 allows remote…
- CVE-2004-0551Cisco CatOS 5.x before 5.5(20) through 8.x before 8.2(2) and…
- CVE-2004-0554Linux kernel 2.4.x and 2.6.x for x86 allows local users to c…
- CVE-2004-0555Buffer overflow in (1) queue.c and (2) queued.c in queue bef…
- CVE-2004-0556Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2004-0557Multiple buffer overflows in the st_wavstartread function in…
- CVE-2004-0558The Internet Printing Protocol (IPP) implementation in CUPS …
- CVE-2004-0559The maketemp.pl script in Usermin 1.070 and 1.080 allows loc…
Are you affected by CVE-2004-0552?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
