VulnerabilityModified
CVE-2008-0434
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
HIGH 9.3EPSS 10.4%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.4%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbitrary code via format string specifiers in the CNHO command.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.35% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- gecad technologies/axigen mail server
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.htmlExploit
- http://secunia.com/advisories/28562Vendor Advisory
- http://securityreason.com/securityalert/3570
- http://www.securityfocus.com/archive/1/486722/100/0/threaded
- http://www.securityfocus.com/bid/27363Exploit
- http://www.vupen.com/english/advisories/2008/0237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39803
- https://www.exploit-db.com/exploits/4947
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-January/059788.htmlExploit
- http://secunia.com/advisories/28562Vendor Advisory
- http://securityreason.com/securityalert/3570
- http://www.securityfocus.com/archive/1/486722/100/0/threaded
- http://www.securityfocus.com/bid/27363Exploit
- http://www.vupen.com/english/advisories/2008/0237
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39803
- https://www.exploit-db.com/exploits/4947
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.