6.8
CVE-2007-2958
- EPSS 4.35%
- Veröffentlicht 27.08.2007 17:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle PSIRT-CNA@flexerasoftware.com
- CVE-Watchlists
- Unerledigt
Format string vulnerability in the inc_put_error function in src/inc.c in Sylpheed 2.4.4, and Sylpheed-Claws (Claws Mail) 1.9.100 and 2.10.0, allows remote POP3 servers to execute arbitrary code via format string specifiers in crafted replies.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sylpheed-claws ≫ Sylpheed-claws Version1.9.100
Sylpheed-claws ≫ Sylpheed-claws Version2.10.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.35% | 0.885 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|