Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2005-2933

Опубликовано: 13 окт. 2005
Источник: nvd
CVSS2: 7.5
EPSS Средний

Описание

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:university_of_washington:uw-imap:*:*:*:*:*:*:*:*
Версия до 2004f (включая)
cpe:2.3:a:university_of_washington:uw-imap:2004:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:uw-imap:2004a:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:uw-imap:2004b:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:uw-imap:2004c:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:uw-imap:2004d:*:*:*:*:*:*:*
cpe:2.3:a:university_of_washington:uw-imap:2004e:*:*:*:*:*:*:*

EPSS

Процентиль: 97%
0.35083
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

ubuntu
почти 20 лет назад

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

redhat
почти 20 лет назад

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

debian
почти 20 лет назад

Buffer overflow in the mail_valid_net_parse_work function in mail.c fo ...

github
больше 3 лет назад

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

EPSS

Процентиль: 97%
0.35083
Средний

7.5 High

CVSS2

Дефекты

NVD-CWE-Other