CVE-2004-0777
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 11%
from disclosure to weapon14 days
Published on NVDAug 19
1st PoC+14d
exploitation probability
11%top 4% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/432⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://security.gentoo.org/glsa/glsa-200408-19.xmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17034http://www.securityfocus.com/bid/10976http://www.trustix.net/errata/2004/0043/http://www.verisigninc.com/en_US/products-and-services/network-intelligence-availability/idefense/public-vulnerability-reports/articles/index.xhtml?id=131