CVE-2004-1558
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 71%
from disclosure to weapon0 days
Published on NVDFeb 20
1st PoCOct 15
metasploitSep 27
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) POP3 USER command or (2) SMTP request.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/16818unverifiedexploitdbwww.exploit-db.com/exploits/577unverifiedexploitdbwww.exploit-db.com/exploits/582unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://dbeusee.home.comcast.net/history.htmlhttp://marc.info/?l=bugtraq&m=109630699829536&w=2http://secunia.com/advisories/12660http://securitytracker.com/alerts/2004/Sep/1011426.htmlhttps://exchange.xforce.ibmcloud.com/vulnerabilities/17515https://exchange.xforce.ibmcloud.com/vulnerabilities/17518http://www.attrition.org/pipermail/vim/2006-October/001089.htmlhttp://www.hat-squad.com/en/000075.htmlhttp://www.osvdb.org/10366http://www.osvdb.org/10367http://www.securityfocus.com/bid/11256