← Vulnerability feed

Vulnerability record · CVE-2004-1342 · published 27 April 2005

CVE-2004-1342: Cvs vulnerability

CCvs · Cvs

CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

7.5 CVSS 2.0 High EPSS 2.3% · top 17.5%
7.5CVSS 2.0 base score
2.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

CVS 1.12 and earlier on Debian GNU/Linux, when using the repouid patch, allows remote attackers to bypass authentication via the pserver access method.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1342 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2012-0804Cvs memory buffer overflow vulnerabilityHeap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of s…EPSS 8.5%10.0CVE-2004-0414Cvs vulnerabilityCVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle malformed "Entry" lines, which prevents a NULL terminator from being …EPSS 4.0%10.0CVE-2004-0416Cvs memory buffer overflow vulnerabilityDouble free vulnerability for the error_prog_name string in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, may allow remote attackers to exec…EPSS 13%10.0CVE-2004-0418Cvs vulnerabilityserve_notify in CVS 1.12.x through 1.12.8, and 1.11.x through 1.11.16, does not properly handle empty data lines, which may allow remote attackers to…EPSS 5.7%7.5CVE-2005-0753Cvs vulnerabilityBuffer overflow in CVS before 1.11.20 allows remote attackers to execute arbitrary code.EPSS 4.7%7.5CVE-2004-0396CVS pserver heap buffer overflow allows remote code executionCVS versions 1.11.x through 1.11.15 and 1.12.x through 1.12.7 contain a heap-based buffer overflow that is triggered when the pserver mechanism proce…EPSS 68%analysed7.5CVE-2003-0977Cvs vulnerabilityCVS server before 1.11.10 may allow attackers to cause the CVS server to create directories and files in the file system root directory via malformed…EPSS 2.3%7.5CVE-2003-0015Freebsd double free vulnerabilityDouble-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a ma…EPSS 24%

Source: NIST National Vulnerability Database (record CVE-2004-1342), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.