VDB
CVE-2023-52159
CVE-2023-52159
PUBLISHED
CVSS 7.5 HIGH
A stack-based buffer overflow vulnerability in gross 0.9.3 through 1.x before 1.0.4 allows remote attackers to trigger a denial of service (grossd daemon crash) or potentially execute arbitrary code in grossd via crafted SMTP transaction parameters that cause an incorrect strncat for a log entry.
EPSS 1.05% · 62.0th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
1.05%
62.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| debian | debian_linux | 10.0 |
| n/a | n/a | n/a |
| bizdelnick | gross | 0.9.3 |
Timeline
- Mar 18, 2024 CVE Published
- Mar 18, 2024 EPSS Score
- Apr 13, 2024 EPSS Score
- Jun 4, 2024 EPSS Score
- Jun 30, 2024 EPSS Score
- Jul 27, 2024 EPSS Score
- Sep 17, 2024 EPSS Score
- Oct 13, 2024 EPSS Score
- Nov 8, 2024 EPSS Score
- Dec 5, 2024 EPSS Score
- Jan 26, 2025 EPSS Score
- Feb 21, 2025 EPSS Score