Back

CVE-2004-0777

Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attackers to execute arbitrary code.

Published: Oct 20, 2004 Modified: Jun 16, 2026
CWE-134

CVSS Metrics

Affected Products (8)

Vendor Product Version
inter7 courier-imap 1.6
inter7 courier-imap 1.7
inter7 courier-imap 2.0.0
inter7 courier-imap 2.1
inter7 courier-imap 2.1.1
inter7 courier-imap 2.1.2
inter7 courier-imap 2.2.0
inter7 courier-imap 2.2.1

GitHub Security Advisory GHSA-25j9-9wxp-hpp7

Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 10.91%

Top 5% most likely to be exploited

Threat Score 33.3 / 100

Data Sources

NVD EPSS GitHub