VDB
CVE-2005-2933
CVE-2005-2933
PUBLISHED
CVSS 7.5 HIGH
Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.
EPSS 8.46% · 94.5th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
8.46%
94.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| university_of_washington | uw-imap | 0, 2004, 2004b |
Timeline
- Oct 13, 2005 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 27, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- MDKSA-2005:194 vendor-advisory
- 17062 third-party-advisory
- 20051201-01-U vendor-advisory
- RHSA-2006:0501 vendor-advisory
- FLSA:170411 vendor-advisory
- 17928 third-party-advisory
- 17336 third-party-advisory
- 20210 third-party-advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm url
- 18554 third-party-advisory
- RHSA-2005:848 vendor-advisory
- VU#933601 third-party-advisory
- ftp://patches.sgi.com/support/free/security/advisories/20060501-01-U.asc technical
- http://rhn.redhat.com/errata/RHSA-2006-0276.html technical
- http://rhn.redhat.com/errata/RHSA-2006-0549.html technical
- http://secunia.com/advisories/17148 technical
- http://secunia.com/advisories/17215 technical
- http://secunia.com/advisories/17950 technical
- http://secunia.com/advisories/20951 technical
- http://securityreason.com/securityalert/47 technical
…and 27 more