CVE-2003-0300
published 2003-06-16CVE-2003-0300: The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause…
PriorityP416medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
3.36%
87.4th percentile
The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | outlook_express | — | — |
| mozilla | mozilla | — | — |
| mozilla | mozilla | — | — |
| mutt | mutt | — | — |
| qualcomm | eudora | — | — |
| stuart_parmenter | balsa | — | — |
| sylpheed | sylpheed_email_client | — | — |
| university_of_washington | pine | — | — |
| ximian | evolution | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
exploitdb·2003-03-19
CVE-2003-0130 Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
Ximian Evolution 1.x - MIME image/* Content-Type Data Inclusion
---
source: https://www.securityfocus.com/bid/7119/info
Ximian Evolution does not properly validate MIME image/* Content-Type fields. If an email message contains an image/* Content-Type, any type of data can be embedded where the image information is expected. This can be used to embed HTML tags that will be rendered by GTKHtml, bypass policies, or invoke bonobo components to handle external content types.
The following example will cause heap corruption:
>From [email protected] Wed Mar 5 14:06:02 2003
Subject: xxx
From: X X. X
To: [email protected]
Content-Type: multipart/mixed; boundary="=-mTDu5zdJIsixETTwCF5Y"
Message-Id:
Mime-Version: 1.0
Date: 05 Mar 2003 14:09:14 -0300
--=-mTDu5zdJIsixETTwCF5Y
Content-Type: text/plain
C
Exploit-DB
Ximian Evolution 1.x - UUEncoding Denial of Service
exploitdb·2003-03-17
CVE-2003-0128 Ximian Evolution 1.x - UUEncoding Denial of Service
Ximian Evolution 1.x - UUEncoding Denial of Service
---
source: https://www.securityfocus.com/bid/7118/info
A vulnerability has been discovered in the Ximian Evolution Mail User Agent (MUA). The problem occurs when the mailer attempts to process a maliciously encoded e-mail message. When attempting to decode the message, the MUA will repeatedly attempt to allocate memory, resulting in system resource exhaustion and will eventually crash.
This vulnerability affects Ximian Evolution version 1.2.2 and earlier.
From [email protected] Wed Mar 5 14:06:02 2003
Subject: xxx
From: X X. X
To: [email protected]
Content-Type: multipart/mixed; boundary="=-mTDu5zdJIsixETTwCF5Y"
Message-Id:
Mime-Version: 1.0
Date: 05 Mar 2003 14:09:14 -0300
--=-mTDu5zdJIsixETTwCF5Y
Content-Disposition: inline; filename=n
No writeups or analysis indexed.
2003-06-16
Published