CVE-2010-2813

functions/imap_general.php in SquirrelMail before 1.4.21 does not properly handle 8-bit characters in passwords, which allows remote attackers to cause a denial of service (disk consumption) by making many IMAP login attempts with different usernames, leading to the creation of many preferences files.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 86%
VendorProductVersion
squirrelmailsquirrelmail
𝑥
≤ 1.4.20
squirrelmailsquirrelmail
1.4
squirrelmailsquirrelmail
1.4:rc1
squirrelmailsquirrelmail
1.4.0
squirrelmailsquirrelmail
1.4.0:rc1
squirrelmailsquirrelmail
1.4.0:rc2a
squirrelmailsquirrelmail
1.4.0-r1
squirrelmailsquirrelmail
1.4.0_rc1:_rc1
squirrelmailsquirrelmail
1.4.0_rc2a:_rc2a
squirrelmailsquirrelmail
1.4.1
squirrelmailsquirrelmail
1.4.2
squirrelmailsquirrelmail
1.4.2-r1
squirrelmailsquirrelmail
1.4.2-r2
squirrelmailsquirrelmail
1.4.2-r3
squirrelmailsquirrelmail
1.4.2-r4
squirrelmailsquirrelmail
1.4.2-r5
squirrelmailsquirrelmail
1.4.3
squirrelmailsquirrelmail
1.4.3:r3
squirrelmailsquirrelmail
1.4.3:rc1
squirrelmailsquirrelmail
1.4.3_r3:_r3
squirrelmailsquirrelmail
1.4.3_rc1:_rc1
squirrelmailsquirrelmail
1.4.3_rc1:_rc1
squirrelmailsquirrelmail
1.4.3a:a
squirrelmailsquirrelmail
1.4.3aa:aa
squirrelmailsquirrelmail
1.4.4
squirrelmailsquirrelmail
1.4.4:rc1
squirrelmailsquirrelmail
1.4.4_rc1:_rc1
squirrelmailsquirrelmail
1.4.5
squirrelmailsquirrelmail
1.4.5:rc1
squirrelmailsquirrelmail
1.4.5_rc1:_rc1
squirrelmailsquirrelmail
1.4.6
squirrelmailsquirrelmail
1.4.6:rc1
squirrelmailsquirrelmail
1.4.6_cvs:_cvs
squirrelmailsquirrelmail
1.4.6_rc1:_rc1
squirrelmailsquirrelmail
1.4.7
squirrelmailsquirrelmail
1.4.8
squirrelmailsquirrelmail
1.4.8.4fc6:fc6
squirrelmailsquirrelmail
1.4.9
squirrelmailsquirrelmail
1.4.9a:a
squirrelmailsquirrelmail
1.4.10
squirrelmailsquirrelmail
1.4.10a:a
squirrelmailsquirrelmail
1.4.11
squirrelmailsquirrelmail
1.4.12
squirrelmailsquirrelmail
1.4.13
squirrelmailsquirrelmail
1.4.15
squirrelmailsquirrelmail
1.4.15:rc1
squirrelmailsquirrelmail
1.4.15_rc1:_rc1
squirrelmailsquirrelmail
1.4.15rc1:rc1
squirrelmailsquirrelmail
1.4.16
squirrelmailsquirrelmail
1.4.17
squirrelmailsquirrelmail
1.4.18
squirrelmailsquirrelmail
1.4.19
squirrelmailsquirrelmail
1.4_rc1:_rc1
squirrelmailsquirrelmail
1.44
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
squirrelmail
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
hardy
ignored
dapper
ignored
Common Weakness Enumeration
References