VulnerabilityModified
CVE-2004-2495
The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.
HIGH 7.8EPSS 2.03%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 2.03% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- code-crafters/ability mail server
- Source
- cve@mitre.org
References
- http://members.lycos.co.uk/r34ct/main/Ability_mail_server_1.18.txtVendor Advisory
- http://secunia.com/advisories/12039Vendor Advisory
- http://securitytracker.com/id?1010672Vendor Advisory
- http://www.osvdb.org/7719
- http://www.securityfocus.com/bid/10695
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16677
- http://members.lycos.co.uk/r34ct/main/Ability_mail_server_1.18.txtVendor Advisory
- http://secunia.com/advisories/12039Vendor Advisory
- http://securitytracker.com/id?1010672Vendor Advisory
- http://www.osvdb.org/7719
- http://www.securityfocus.com/bid/10695
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16677
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.