Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2005-0198

EPSS 26.66% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2005-0198

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
A logic error in the CRAM-MD5 code for the University of Washington IMAP (UW-IMAP) server, when Challenge-Response Authentication Mechanism with MD5 (CRAM-MD5) is enabled, does not properly enforce all the required conditions for successful authentication, which allows remote attackers to authenticate as arbitrary users.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
University Of Washington IMAP Server CRAM-MD5远程身份验证绕过漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
University of Washington IMAP (UW-IMAP) server的CRAM-MD5代码中存在逻辑错误,在启用"口令-应答认证机制"MD5 (CRAM-MD5)的情况下,并不能针对成功的身份验证正确强制所有要求的条件,从而远程攻击者可以作为任意用户进行身份验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2005-0198

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2005-0198

登录查看更多情报信息。

Same Patch Batch · n/a · 2005-02-06 · 65 CVEs total

CVE-2005-0195Cisco IOS远程拒绝服务漏洞
CVE-2005-0221Gallery login.php 跨站脚本攻击漏洞
CVE-2005-0224HP Virtualvault 拒绝服务漏洞
CVE-2005-0223Tru64 UNIX漏洞
CVE-2005-0222Gallery信息泄露漏洞
CVE-2005-0211Squid Proxy WCCP recvfrom()远程缓冲区溢出漏洞
CVE-2005-0200TikiWiki未明安全漏洞
CVE-2005-0199ngIRCd远程缓冲区溢出漏洞
CVE-2005-0197Cisco IOS畸形MPLS包远程拒绝服务漏洞
CVE-2005-0196Cisco IOS畸形BGP包远程拒绝服务漏洞
CVE-2005-0212Amp II 3D远程拒绝服务漏洞
CVE-2005-0194Squid 权限管理和访问控制漏洞
CVE-2005-0193Apple MacOS iSync mRouter 缓存区溢出漏洞
CVE-2005-0192RealPlayer解析Skin文件名目录遍历漏洞
CVE-2005-0191RealNetwork RealPlayer RealMetadataPackage 缓冲区溢出漏洞
CVE-2005-0190RealNetworks Realplayer远程任意文件删除漏洞
CVE-2005-0189RealNetworks Realplayer 'ShowPreferences'远程缓冲区溢出漏洞
CVE-2005-0188AtHoc Toolbar远程缓冲区及格式串漏洞
CVE-2005-0187AtHoc Toolbar远程缓冲区及格式串漏洞
CVE-2005-0186Cisco IOS SCCP 拒绝服务漏洞

Showing top 20 of 65 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2005-0198

No comments yet


Leave a comment