VulnerabilityModified
CVE-2006-0537
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.
HIGH 7.5EPSS 41.5%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 41.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execute arbitrary code via a long RCPT TO argument.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 41.50% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- kinesphere corporation/exchange pop3
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0040.html
- http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.plExploit
- http://secunia.com/advisories/18687Vendor Advisory
- http://securityreason.com/securityalert/408
- http://securitytracker.com/id?1015580
- http://www.osvdb.org/22907
- http://www.securityfocus.com/bid/16485Exploit
- http://www.vupen.com/english/advisories/2006/0437
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24477
- https://www.exploit-db.com/exploits/1466
- http://archives.neohapsis.com/archives/bugtraq/2006-02/0040.html
- http://downloads.securityfocus.com/vulnerabilities/exploits/exchangepop3.plExploit
- http://secunia.com/advisories/18687Vendor Advisory
- http://securityreason.com/securityalert/408
- http://securitytracker.com/id?1015580
- http://www.osvdb.org/22907
- http://www.securityfocus.com/bid/16485Exploit
- http://www.vupen.com/english/advisories/2006/0437
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24477
- https://www.exploit-db.com/exploits/1466
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.