Lucene search

K
nvd[email protected]NVD:CVE-2005-0021
HistoryMay 02, 2005 - 4:00 a.m.

CVE-2005-0021

2005-05-0204:00:00
web.nvd.nist.gov
1

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

56.3%

Multiple buffer overflows in Exim before 4.43 may allow attackers to execute arbitrary code via (1) an IPv6 address with more than 8 components, as demonstrated using the -be command line option, which triggers an overflow in the host_aton function, or (2) the -bh command line option or dnsdb PTR lookup, which triggers an overflow in the dns_build_reverse function.

Affected configurations

Nvd
Node
university_of_cambridgeeximRange4.40
OR
university_of_cambridgeeximMatch4.41
OR
university_of_cambridgeeximMatch4.42
VendorProductVersionCPE
university_of_cambridgeexim*cpe:2.3:a:university_of_cambridge:exim:*:*:*:*:*:*:*:*
university_of_cambridgeexim4.41cpe:2.3:a:university_of_cambridge:exim:4.41:*:*:*:*:*:*:*
university_of_cambridgeexim4.42cpe:2.3:a:university_of_cambridge:exim:4.42:*:*:*:*:*:*:*

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.7

Confidence

Low

EPSS

0.002

Percentile

56.3%