peter bassill · operator
$ cve CVE-2005-2409 JSON

CVE-2005-2409 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 9.9% (pctl 95)

Patch early

A public exploit exists.

Description

Format string vulnerability in util.c in nbsmtp 0.99 and earlier, while running in debug mode, allows remote attackers to execute arbitrary code via format string specifiers that are not properly handled in a syslog call.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS9.94% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2005-08-01
Last modified2026-06-16

Affected (1)

VendorProduct
nbsmtpnbsmtp

Public exploits

SourceTitleDate
exploit-dbnbSMTP 0.99 - 'util.c' Client-Side Command Execution2005-08-05

References

→ the Explorer  ·  watch your stack  ·  NVD