// For flags

CVE-2005-2933

 

Severity Score

7.5
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer overflow in the mail_valid_net_parse_work function in mail.c for Washington's IMAP Server (UW-IMAP) before imap-2004g allows remote attackers to execute arbitrary code via a mailbox name containing a single double-quote (") character without a closing quote, which causes bytes after the double-quote to be copied into a buffer indefinitely.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2005-09-15 CVE Reserved
  • 2005-10-06 CVE Published
  • 2024-08-07 CVE Updated
  • 2024-09-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
References (46)
URL Tag Source
http://secunia.com/advisories/17148 Third Party Advisory
http://secunia.com/advisories/17152 Third Party Advisory
http://secunia.com/advisories/17215 Third Party Advisory
http://secunia.com/advisories/17276 Third Party Advisory
http://secunia.com/advisories/17336 Third Party Advisory
http://secunia.com/advisories/17483 Third Party Advisory
http://secunia.com/advisories/17928 Third Party Advisory
http://secunia.com/advisories/17930 Third Party Advisory
http://secunia.com/advisories/17950 Third Party Advisory
http://secunia.com/advisories/18554 Third Party Advisory
http://secunia.com/advisories/19832 Third Party Advisory
http://secunia.com/advisories/20210 Third Party Advisory
http://secunia.com/advisories/20222 Third Party Advisory
http://secunia.com/advisories/20951 Third Party Advisory
http://secunia.com/advisories/21252 Third Party Advisory
http://secunia.com/advisories/21564 Third Party Advisory
http://securityreason.com/securityalert/47 Third Party Advisory
http://securitytracker.com/id?1015000 Vdb Entry
http://support.avaya.com/elmodocs2/security/ASA-2006-129.htm X_refsource_confirm
http://support.avaya.com/elmodocs2/security/ASA-2006-160.htm X_refsource_confirm
http://www.kb.cert.org/vuls/id/933601 Third Party Advisory
http://www.securityfocus.com/bid/15009 Vdb Entry
http://www.vupen.com/english/advisories/2006/2685 Vdb Entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/22518 Vdb Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9858 Signature
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
<= 2004f
Search vendor "University Of Washington" for product "Uw-imap" and version " <= 2004f"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004
Search vendor "University Of Washington" for product "Uw-imap" and version "2004"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004a
Search vendor "University Of Washington" for product "Uw-imap" and version "2004a"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004b
Search vendor "University Of Washington" for product "Uw-imap" and version "2004b"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004c
Search vendor "University Of Washington" for product "Uw-imap" and version "2004c"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004d
Search vendor "University Of Washington" for product "Uw-imap" and version "2004d"
-
Affected
University Of Washington
Search vendor "University Of Washington"
Uw-imap
Search vendor "University Of Washington" for product "Uw-imap"
2004e
Search vendor "University Of Washington" for product "Uw-imap" and version "2004e"
-
Affected