cbcvebase.
CVE-2005-0100
published 2005-02-07

CVE-2005-0100: Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote…

PriorityP434high7.5CVSS 2.0
AVNACLAuNCPIPAP
EPSS
4.36%
90.2th percentile
Format string vulnerability in the movemail utility in (1) Emacs 20.x, 21.3, and possibly other versions, and (2) XEmacs 21.4 and earlier, allows remote malicious POP3 servers to execute arbitrary code via crafted packets.

Affected

4 ranges
VendorProductVersion rangeFixed in
debianxemacs21< xemacs21 21.4.16-2 (bookworm)xemacs21 21.4.16-2 (bookworm)
gnuemacs<= 20.0
gnuemacs
gnuxemacs<= 21.4

CVSS provenance

nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.