Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xr7v-hj32-mr4r

Опубликовано: 27 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
redhat
5 дней назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
nvd
5 дней назад

Attacker can send a specifically crafted message before authentication that causes managesieve to allocate large amount of memory. Attacker can force managesieve-login to be unavailable by repeatedly crashing the process. Protect access to managesieve protocol, or install fixed version. No publicly available exploits are known.

CVSS3: 7.5
debian
5 дней назад

Attacker can send a specifically crafted message before authentication ...

EPSS

Процентиль: 15%
0.00047
Низкий

7.5 High

CVSS3

Дефекты

CWE-400