Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2000-0284

13 documents5 sources
Severity
7.5HIGH
EPSS
78.7%
top 0.95%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 16
Latest updateApr 30

Description

Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-rj56-vwqm-8wv9: Buffer overflow in University of Washington imapd version 42022-04-30
CVEList
CVE-2000-0284: Buffer overflow in University of Washington imapd version 42000-04-26

💥Exploits & PoCs

8
Exploit-DB
UoW IMAPd Server - LSUB Buffer Overflow (Metasploit)2010-03-26
Exploit-DB
UoW IMAPd Server 10.234/12.264 - Remote Buffer Overflow2002-08-01
Exploit-DB
WU-IMAP 2000.287(1-2) - Remote Overflow2002-06-25
Exploit-DB
IMAP4rev1 12.261/12.264/2000.284 - 'lsub' Remote Overflow2001-03-03
Exploit-DB
IMAP4rev1 10.190 - Authentication Stack Overflow2001-01-19

🔍Detection Rules

2
Suricata
GPL IMAP find overflow attempt2010-09-23
Suricata
GPL IMAP rename overflow attempt2010-09-23
CVE-2000-0284 (HIGH CVSS 7.5) | Buffer overflow in University of Wa | cvebase.io