CVE-2004-2650

Severity
4.9MEDIUM
EPSS
0.1%
top 78.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 31
Latest updateApr 29

Description

Spooler in Apache Foundation James 2.2.0 allows local users to cause a denial of service (memory consumption) by triggering various error conditions in the retrieve function, which prevents a lock from being released and causes a memory leak.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Apache James Denial of Service2022-04-29
OSV
Apache James Denial of Service2022-04-29
CVEList
CVE-2004-2650: Spooler in Apache Foundation James 22005-12-09
CVE-2004-2650 (MEDIUM CVSS 4.9) | Spooler in Apache Foundation James | cvebase.io