Vulnerability record · CVE-2004-1096 · published 10 January 2005
CVE-2004-1096: Broadcom brightstor arcserve backup vulnerability
Broadcom · Brightstor Arcserve Backup
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
Description
Archive::Zip Perl module before 1.14, when used by antivirus programs such as amavisd-new, allows remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Affected products
22 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://secunia.com/advisories/13038/ | |
| http://www.gentoo.org/security/en/glsa/glsa-200410-31.xml | PatchVendor Advisory |
| http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/492545 | US Government Resource |
| http://www.mandriva.com/security/advisories?name=MDKSA-2004:118 | |
| http://www.securityfocus.com/bid/11448 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17761 | |
| http://secunia.com/advisories/13038/ | |
| http://www.gentoo.org/security/en/glsa/glsa-200410-31.xml | PatchVendor Advisory |
| http://www.idefense.com/application/poi/display?id=153&type=vulnerabilities&flashstatus=true | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/492545 | US Government Resource |
| http://www.mandriva.com/security/advisories?name=MDKSA-2004:118 | |
| http://www.securityfocus.com/bid/11448 | ExploitPatchVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17761 |
Track CVE-2004-1096 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1096), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.