CVE-2004-0777

Courier-IMAP <3.0.3 - RCE

Title source: llm

Description

Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.

Exploits (1)

exploitdb WORKING POC VERIFIED
by ktha · cremotebsd
https://www.exploit-db.com/exploits/432

Scores

EPSS 0.1592
EPSS Percentile 94.8%

Details

CWE
CWE-134
Status published
Products (8)
inter7/courier-imap 1.6
inter7/courier-imap 1.7
inter7/courier-imap 2.0.0
inter7/courier-imap 2.1
inter7/courier-imap 2.1.1
inter7/courier-imap 2.1.2
inter7/courier-imap 2.2.0
inter7/courier-imap 2.2.1
Published Oct 20, 2004
Tracked Since Feb 18, 2026