Vulnerability record · CVE-2000-0284 · published 16 April 2000
CVE-2000-0284: University of Washington imapd 4.7 buffer overflow via LIST command
University Of Washington · Imap
University of Washington imapd version 4.7 contains a buffer overflow that can be triggered through the LIST command or other commands. A user with a valid account can exploit the overflow to execute commands on the server, making this a post-authentication remote code execution issue in an internet-facing mail service.
Description
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote code execution in an internet-facing mail service with a high EPSS score, though exploitation requires valid credentials and no in-the-wild activity is documented.
What it is
University of Washington imapd version 4.7 contains a buffer overflow that can be triggered through the LIST command or other commands. A user with a valid account can exploit the overflow to execute commands on the server, making this a post-authentication remote code execution issue in an internet-facing mail service.
Impact
An attacker with a valid account gains the ability to execute arbitrary commands on the IMAP server, potentially compromising mail data and the host itself. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.
Attack surface
The flaw is reachable over the network through the IMAP service (AV:N, AC:L). Exploitation requires a valid account on the server, so authentication is needed; the description does not indicate any user interaction beyond issuing the crafted command.
Exploitation
The record is not listed in CISA KEV and no ransomware association is documented. EPSS shows a high 30-day probability (0.683, 99.3rd percentile), but the references are only vendor advisories and mailing list posts, with no public exploit code or in-the-wild confirmation stated.
What to do
- Upgrade or patch imapd beyond version 4.7 per the vendor advisory; treat 4.7 as affected.
- If patching is not immediately possible, restrict IMAP access to trusted networks and disable or limit untrusted accounts.
- Enforce strong authentication and monitor for anomalous account use, since exploitation requires a valid account.
- Consider running the IMAP service under a low-privilege account and with OS-level sandboxing to limit command execution impact.
Detection
- Monitor IMAP server logs for malformed or unusually long LIST commands and other command arguments.
- Alert on unexpected child processes or shell activity spawned by the imapd process.
- Baseline normal IMAP session behavior per account and flag sessions issuing abnormal command sequences or volumes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0284 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.