{"api_version":"1","generated_at":"2026-07-23T06:54:03+00:00","cve":"CVE-2007-0157","urls":{"html":"https://cve.report/CVE-2007-0157","api":"https://cve.report/api/cve/CVE-2007-0157.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0157","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0157"},"summary":{"title":"CVE-2007-0157","description":"Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-01-09 21:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html","name":"http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2007/0172","name":"http://www.vupen.com/english/advisories/2007/0172","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#404723 - src/ne_uri.c:ne_uri_parse():179 (uri_lookup(x) macro) - SIGSERV when parsing a non-ASCII character (>128) - Debian Bug report logs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/39247","name":"http://osvdb.org/39247","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2007/0362","name":"http://www.vupen.com/english/advisories/2007/0362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail - OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://mailman.webdav.org/pipermail/neon/2007-January/002362.html","name":"http://mailman.webdav.org/pipermail/neon/2007-January/002362.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[neon] invalid chars cause sigserv in neon","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2","name":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#404723 - src/ne_uri.c:ne_uri_parse():179 (uri_lookup(x) macro) - SIGSERV when parsing a non-ASCII character (>128) - Debian Bug report logs","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"http://www.novell.com/linux/security/advisories/2007_02_sr.html","name":"http://www.novell.com/linux/security/advisories/2007_02_sr.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Announcement","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:013","name":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:013","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Advisories - Mandriva Linux","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.webdav.org/cadaver/","name":"http://www.webdav.org/cadaver/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"cadaver - command-line WebDAV client","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23751","name":"http://secunia.com/advisories/23751","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"neon \"ne_uri_parse()\" Denial of Service - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23763","name":"http://secunia.com/advisories/23763","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Mandriva update for libneon - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23984","name":"http://secunia.com/advisories/23984","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SUSE Update for Multiple Packages - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/22035","name":"http://www.securityfocus.com/bid/22035","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neon LibNeon Non-Ascii Character URI Data Denial Of Service Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2","name":"CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2","refsource":"MITRE","tags":[],"title":"","mime":"text/x-diff","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0157","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0157","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"157","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"neon","cpe5":"neon","cpe6":"0.26.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"157","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"neon","cpe5":"neon","cpe6":"0.26.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"157","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"neon","cpe5":"neon","cpe6":"0.26.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2007-0157","organization":"Red Hat","lastmodified":"2007-01-15","contributor":"Mark J Cox","statementText":"Not vulnerable. This issue does not affect the older versions of neon as shipped with Red Hat Enterprise Linux 2.1, 3, and 4. This issue also does not affect the older versions of neon included in the cadaver package.","cve_year":"2007","cve_id":"157","crc32":"7c851262"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:16.464Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23984","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23984"},{"name":"[neon] 20070107 invalid chars cause sigserv in neon","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://mailman.webdav.org/pipermail/neon/2007-January/002362.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.webdav.org/cadaver/"},{"name":"[cadaver] 20070123 release 0.22.5","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html"},{"name":"MDKSA-2007:013","tags":["vendor-advisory","x_refsource_MANDRIVA","x_transferred"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:013"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723"},{"name":"SUSE-SR:2007:002","tags":["vendor-advisory","x_refsource_SUSE","x_transferred"],"url":"http://www.novell.com/linux/security/advisories/2007_02_sr.html"},{"name":"22035","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22035"},{"name":"ADV-2007-0172","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0172"},{"name":"23763","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23763"},{"name":"ADV-2007-0362","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0362"},{"name":"23751","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23751"},{"name":"39247","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/39247"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-01-07T00:00:00.000Z","descriptions":[{"lang":"en","value":"Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-01-19T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23984","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23984"},{"name":"[neon] 20070107 invalid chars cause sigserv in neon","tags":["mailing-list","x_refsource_MLIST"],"url":"http://mailman.webdav.org/pipermail/neon/2007-January/002362.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723%3Bmsg=5%3Batt=2"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.webdav.org/cadaver/"},{"name":"[cadaver] 20070123 release 0.22.5","tags":["mailing-list","x_refsource_MLIST"],"url":"http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html"},{"name":"MDKSA-2007:013","tags":["vendor-advisory","x_refsource_MANDRIVA"],"url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:013"},{"tags":["x_refsource_CONFIRM"],"url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723"},{"name":"SUSE-SR:2007:002","tags":["vendor-advisory","x_refsource_SUSE"],"url":"http://www.novell.com/linux/security/advisories/2007_02_sr.html"},{"name":"22035","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22035"},{"name":"ADV-2007-0172","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0172"},{"name":"23763","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23763"},{"name":"ADV-2007-0362","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0362"},{"name":"23751","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23751"},{"name":"39247","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/39247"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-0157","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23984","refsource":"SECUNIA","url":"http://secunia.com/advisories/23984"},{"name":"[neon] 20070107 invalid chars cause sigserv in neon","refsource":"MLIST","url":"http://mailman.webdav.org/pipermail/neon/2007-January/002362.html"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2","refsource":"CONFIRM","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi/neon26_0.26.2-3_to_mdx1.diff?bug=404723;msg=5;att=2"},{"name":"http://www.webdav.org/cadaver/","refsource":"CONFIRM","url":"http://www.webdav.org/cadaver/"},{"name":"[cadaver] 20070123 release 0.22.5","refsource":"MLIST","url":"http://mailman.webdav.org/pipermail/cadaver/2007-January/001015.html"},{"name":"MDKSA-2007:013","refsource":"MANDRIVA","url":"http://www.mandriva.com/security/advisories?name=MDKSA-2007:013"},{"name":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723","refsource":"CONFIRM","url":"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=404723"},{"name":"SUSE-SR:2007:002","refsource":"SUSE","url":"http://www.novell.com/linux/security/advisories/2007_02_sr.html"},{"name":"22035","refsource":"BID","url":"http://www.securityfocus.com/bid/22035"},{"name":"ADV-2007-0172","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0172"},{"name":"23763","refsource":"SECUNIA","url":"http://secunia.com/advisories/23763"},{"name":"ADV-2007-0362","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0362"},{"name":"23751","refsource":"SECUNIA","url":"http://secunia.com/advisories/23751"},{"name":"39247","refsource":"OSVDB","url":"http://osvdb.org/39247"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-0157","datePublished":"2007-01-09T21:00:00.000Z","dateReserved":"2007-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:16.464Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-01-09 21:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:N/A:C","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:neon:neon:0.26.0:*:*:*:*:*:*:*","matchCriteriaId":"6CA5EF13-02E0-414E-8076-9E8CF8791C61"},{"vulnerable":true,"criteria":"cpe:2.3:a:neon:neon:0.26.1:*:*:*:*:*:*:*","matchCriteriaId":"D2538986-65F3-4E52-BD74-E31728B14A45"},{"vulnerable":true,"criteria":"cpe:2.3:a:neon:neon:0.26.2:*:*:*:*:*:*:*","matchCriteriaId":"D48115F0-4B06-4C4C-8969-7F0518C46257"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"157","Ordinal":"1","Title":"CVE-2007-0157","CVE":"CVE-2007-0157","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"157","Ordinal":"1","NoteData":"Array index error in the uri_lookup function in the URI parser for neon 0.26.0 to 0.26.2, possibly only on 64-bit platforms, allows remote malicious servers to cause a denial of service (crash) via a URI with non-ASCII characters, which triggers a buffer under-read due to a type conversion error that generates a negative index.","Type":"Description","Title":"CVE-2007-0157"},{"CveYear":"2007","CveId":"157","Ordinal":"2","NoteData":"2007-01-09","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"157","Ordinal":"3","NoteData":"2007-01-19","Type":"Other","Title":"Modified"}]}}}