Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
CVE-2004-0235 Details
Description
Multiple directory traversal vulnerabilities in LHA 1.14 allow remote attackers or local users to create arbitrary files via an LHA archive containing filenames with (1) .. sequences or (2) absolute pathnames with double leading slashes ("//absolute/path").
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| clearswift mailsweeper | 4.0 4.1 4.2 4.3 4.3.3 4.3.4 4.3.5 4.3.6 4.3.6_sp1 4.3.7 4.3.8 4.3.10 4.3.11 4.3.13 |
CPE
Remediation
| |
| f-secure f-secure anti-virus | 4.51 4.52 4.60 5.5 5.41 5.42 5.52 6.21 2003 2004 |
CPE
Remediation
| |
| f-secure f-secure for firewalls | 6.20 |
CPE
Remediation
| |
| f-secure f-secure internet security | 2003 2004 |
CPE
Remediation
| |
| f-secure f-secure personal express | 4.5 4.6 4.7 |
CPE
Remediation
| |
| f-secure internet gatekeeper | 6.31 6.32 |
CPE
Remediation
| |
| rarlab winrar | 3.20 |
CPE
Remediation
| |
| redhat lha | 1.14i-9 |
CPE
Remediation
| |
| sgi propack | 2.4 3.0 |
CPE
Remediation
| |
| stalker cgpmcafee | 3.2 |
CPE
Remediation
| |
| tsugio okamoto lha | 1.14 1.15 1.17 |
CPE
Remediation
| |
| winzip winzip | 9.0 |
CPE
Remediation
| |
| redhat fedora core | core_1.0 |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 16, 2026 | CVE Modified | [email protected] |
| Apr 16, 2026 | [email protected] | |
| Nov 20, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Oct 11, 2017 | CVE Modified | [email protected] |
| Jul 11, 2017 | CVE Modified | [email protected] |
| Oct 18, 2016 | CVE Modified | [email protected] |
| Jan 1, 2004 | Initial Analysis | [email protected] |