POP2 or POP3 server (pop3d) in imap-uw IMAP package on FreeBSD and other operating systems creates lock files with predictable names, which allows local users to cause a denial of service (lack of mail access) for other users by creating lock files for other mail boxes.
📦
imap
Vendor: university_of_washington
Actively Exploited
0
CISA KEV List
PoC / Exploits
4
Code Available
Total RCEs
2
Remote Access
Total CVEs
11
Total Indexed
Avg. EPSS
13.22%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
2.1
CVSS
Severity: LOW
7.5
CVSS
CVE-2000-0847
RCE
Buffer overflow in University of Washington c-client library (used by pine and other programs) allows remote attackers to execute arbitrary commands via a long X-Keywords header.
Severity: HIGH
7.5
CVSS
CVE-2000-0284
Exploit Found
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
Severity: HIGH
10.0
CVSS
CVE-1999-0920
Exploit Found
Buffer overflow in the pop-2d POP daemon in the IMAP package allows remote attackers to gain privileges via the FOLD command.
Severity: HIGH
0.0
CVSS