Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-5467

Опубликовано: 15 окт. 2007
Источник: nvd
CVSS2: 10
EPSS Средний

Описание

Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.

Комментарий

More information available at: http://www.securityfocus.com/bid/26074/discuss

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:extremail:extremail:*:*:*:*:*:*:*:*
Версия до 2.1.1 (включая)

EPSS

Процентиль: 95%
0.17977
Средний

10 Critical

CVSS2

Дефекты

CWE-189

Связанные уязвимости

github
почти 4 года назад

Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" sequences to the pop3 port (110/tcp), which are expanded to "%%s" before being used in the memmove function, possibly due to an incomplete fix for CVE-2001-1078.

EPSS

Процентиль: 95%
0.17977
Средний

10 Critical

CVSS2

Дефекты

CWE-189