Lucene search

K
cveMitreCVE-2005-1682
HistoryMay 25, 2005 - 4:00 a.m.

CVE-2005-1682

2005-05-2504:00:00
CWE-20
mitre
web.nvd.nist.gov
21
javamail api
solstice internet mail server
pop3
email security
authentication
cve-2005-1682

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

54.0%

JavaMail API, as used by Solstice Internet Mail Server POP3 2.0, does not properly validate the message number in the MimeMessage constructor in javax.mail.internet.InternetHeaders, which allows remote authenticated users to read other users’ e-mail messages by modifying the msgno parameter. NOTE: Sun disputes this issue, stating "The report makes references to source code and files that do not exist in the mentioned products.

Affected configurations

Nvd
Node
solsticesolstice_internet_mail_serverMatchpop3_2.0
VendorProductVersionCPE
solsticesolstice_internet_mail_serverpop3_2.0cpe:2.3:a:solstice:solstice_internet_mail_server:pop3_2.0:*:*:*:*:*:*:*

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.002

Percentile

54.0%

Related for CVE-2005-1682