peter bassill · operator
$ cve CVE-2007-5740 JSON

CVE-2007-5740 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 12.4% (pctl 96)

Patch early

A public exploit exists.

Description

The format string protection mechanism in IMAPD for Perdition Mail Retrieval Proxy 1.17 and earlier allows remote attackers to execute arbitrary code via an IMAP tag with a null byte followed by a format string specifier, which is not counted by the mechanism.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS12.38% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-134
On CISA KEVno
Public exploityes
Published2007-10-31
Last modified2026-06-16

Affected (1)

VendorProduct
vergenetperdition mail retrieval proxy

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD