4.3

CVE-2008-5514

Off-by-one error in the rfc822_output_char function in the RFC822BUFFER routines in the University of Washington (UW) c-client library, as used by the UW IMAP toolkit before imap-2007e and other applications, allows context-dependent attackers to cause a denial of service (crash) via an e-mail message that triggers a buffer overflow.

Data is provided by the National Vulnerability Database (NVD)
University Of WashingtonImap Version <= 2007d
University Of WashingtonImap Version2000
University Of WashingtonImap Version2000a
University Of WashingtonImap Version2000b
University Of WashingtonImap Version2000c
University Of WashingtonImap Version2001
University Of WashingtonImap Version2001a
University Of WashingtonImap Version2002
University Of WashingtonImap Version2002a
University Of WashingtonImap Version2002b
University Of WashingtonImap Version2002c
University Of WashingtonImap Version2002d
University Of WashingtonImap Version2002e
University Of WashingtonImap Version2002f
University Of WashingtonImap Version2004
University Of WashingtonImap Version2004a
University Of WashingtonImap Version2004b
University Of WashingtonImap Version2004c
University Of WashingtonImap Version2004d
University Of WashingtonImap Version2004e
University Of WashingtonImap Version2004f
University Of WashingtonImap Version2004g
University Of WashingtonImap Version2006
University Of WashingtonImap Version2006a
University Of WashingtonImap Version2006b
University Of WashingtonImap Version2006c
University Of WashingtonImap Version2006d
University Of WashingtonImap Version2006e
University Of WashingtonImap Version2006f
University Of WashingtonImap Version2006g
University Of WashingtonImap Version2006h
University Of WashingtonImap Version2006i
University Of WashingtonImap Version2006j
University Of WashingtonImap Version2006k
University Of WashingtonImap Version2007
University Of WashingtonImap Version2007a
University Of WashingtonImap Version2007b
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.07% 0.757
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:N/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.