{"api_version":"1","generated_at":"2026-07-23T13:12:03+00:00","cve":"CVE-2005-1523","urls":{"html":"https://cve.report/CVE-2005-1523","api":"https://cve.report/api/cve/CVE-2005-1523.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2005-1523","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2005-1523"},"summary":{"title":"CVE-2005-1523","description":"Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.","state":"PUBLISHED","assigner":"mitre","published_at":"2005-05-26 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1014052","name":"http://securitytracker.com/id?1014052","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - GNU Mailutils Buffer Overflow and Format String Bugs Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/15442","name":"http://secunia.com/advisories/15442","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Mailutils Four Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities","name":"http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Accenture | Let there be change","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.debian.org/security/2005/dsa-732","name":"http://www.debian.org/security/2005/dsa-732","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Debian -- Security Information -- DSA-732-1 mailutils","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/13764","name":"http://www.securityfocus.com/bid/13764","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"GNU Mailutils Imap4D Command Tag Remote Format String Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2005-1523","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2005-1523","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2005","cve_id":"1523","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"mailutils","cpe6":"0.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2005","cve_id":"1523","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gnu","cpe5":"mailutils","cpe6":"0.6","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T21:51:50.475Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1014052","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1014052"},{"name":"20050525 GNU Mailutils 0.6 imap4d Format String Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE","x_transferred"],"url":"http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities"},{"name":"15442","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15442"},{"name":"DSA-732","tags":["vendor-advisory","x_refsource_DEBIAN","x_transferred"],"url":"http://www.debian.org/security/2005/dsa-732"},{"name":"13764","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/13764"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2005-05-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2005-06-04T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1014052","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1014052"},{"name":"20050525 GNU Mailutils 0.6 imap4d Format String Vulnerability","tags":["third-party-advisory","x_refsource_IDEFENSE"],"url":"http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities"},{"name":"15442","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15442"},{"name":"DSA-732","tags":["vendor-advisory","x_refsource_DEBIAN"],"url":"http://www.debian.org/security/2005/dsa-732"},{"name":"13764","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/13764"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2005-1523","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1014052","refsource":"SECTRACK","url":"http://securitytracker.com/id?1014052"},{"name":"20050525 GNU Mailutils 0.6 imap4d Format String Vulnerability","refsource":"IDEFENSE","url":"http://www.idefense.com/application/poi/display?id=246&type=vulnerabilities"},{"name":"15442","refsource":"SECUNIA","url":"http://secunia.com/advisories/15442"},{"name":"DSA-732","refsource":"DEBIAN","url":"http://www.debian.org/security/2005/dsa-732"},{"name":"13764","refsource":"BID","url":"http://www.securityfocus.com/bid/13764"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2005-1523","datePublished":"2005-05-26T04:00:00.000Z","dateReserved":"2005-05-12T00:00:00.000Z","dateUpdated":"2024-08-07T21:51:50.475Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2005-05-26 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gnu:mailutils:0.5:*:*:*:*:*:*:*","matchCriteriaId":"848F9FC2-578F-42FF-A333-011BB779F4BF"},{"vulnerable":true,"criteria":"cpe:2.3:a:gnu:mailutils:0.6:*:*:*:*:*:*:*","matchCriteriaId":"5D061351-9F01-4F19-A323-60DC9CD2C915"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2005","CveId":"1523","Ordinal":"1","Title":"CVE-2005-1523","CVE":"CVE-2005-1523","Year":"2005"},"notes":[{"CveYear":"2005","CveId":"1523","Ordinal":"1","NoteData":"Format string vulnerability in imap4d server in GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows remote attackers to execute arbitrary code via format string specifiers in the command tag for IMAP commands.","Type":"Description","Title":"CVE-2005-1523"},{"CveYear":"2005","CveId":"1523","Ordinal":"2","NoteData":"2005-05-26","Type":"Other","Title":"Published"},{"CveYear":"2005","CveId":"1523","Ordinal":"3","NoteData":"2005-06-04","Type":"Other","Title":"Modified"}]}}}