Lucene search

K
cve[email protected]CVE-2002-1580
HistoryJun 14, 2004 - 4:00 a.m.

CVE-2002-1580

2004-06-1404:00:00
web.nvd.nist.gov
28
In Wild
cve-2002-1580
integer overflow
buffer overflow
cyrus imap server
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.9 High

AI Score

Confidence

High

0.426 Medium

EPSS

Percentile

97.3%

Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code via a large length value that facilitates a buffer overflow attack, a different vulnerability than CVE-2002-1347.

Affected configurations

NVD
Node
carnegie_mellon_universitycyrus_imap_serverMatch1.4
OR
carnegie_mellon_universitycyrus_imap_serverMatch1.5.19
OR
carnegie_mellon_universitycyrus_imap_serverMatch2.0.12
OR
carnegie_mellon_universitycyrus_imap_serverMatch2.0.16
OR
carnegie_mellon_universitycyrus_imap_serverMatch2.1.9
OR
carnegie_mellon_universitycyrus_imap_serverMatch2.1.10

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

9.9 High

AI Score

Confidence

High

0.426 Medium

EPSS

Percentile

97.3%