CVE-2004-2460

5 documents5 sources
Severity
5.0MEDIUM
EPSS
0.9%
top 24.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to cause a denial of service (application crash) via an "infinite" Unique IDentification Listing (UIDL) list.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages2 packages

Debiangnubiff< 2.0.0+3
NVDgnu/gnubiff10 versions+9

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jc3q-h6j6-c49r: Unknown vulnerability in POP3 in gnubiff before 22022-04-29
CVEList
CVE-2004-2460: Unknown vulnerability in POP3 in gnubiff before 22005-08-20
OSV
CVE-2004-2460: Unknown vulnerability in POP3 in gnubiff before 22004-12-31

📋Vendor Advisories

1
Debian
CVE-2004-2460: gnubiff - Unknown vulnerability in POP3 in gnubiff before 2.0.0 allows remote attackers to...2004