← Vulnerability feed

Vulnerability record · CVE-2000-0284 · published 16 April 2000

CVE-2000-0284: University of Washington imapd 4.7 buffer overflow via LIST command

University Of Washington · Imap

University of Washington imapd version 4.7 contains a buffer overflow that can be triggered through the LIST command or other commands. A user with a valid account can exploit the overflow to execute commands on the server, making this a post-authentication remote code execution issue in an internet-facing mail service.

7.5 CVSS 2.0 High EPSS 68% · top 0.7%
7.5CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via LIST or other commands.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution in an internet-facing mail service with a high EPSS score, though exploitation requires valid credentials and no in-the-wild activity is documented.

What it is

University of Washington imapd version 4.7 contains a buffer overflow that can be triggered through the LIST command or other commands. A user with a valid account can exploit the overflow to execute commands on the server, making this a post-authentication remote code execution issue in an internet-facing mail service.

Impact

An attacker with a valid account gains the ability to execute arbitrary commands on the IMAP server, potentially compromising mail data and the host itself. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as partial.

Attack surface

The flaw is reachable over the network through the IMAP service (AV:N, AC:L). Exploitation requires a valid account on the server, so authentication is needed; the description does not indicate any user interaction beyond issuing the crafted command.

Exploitation

The record is not listed in CISA KEV and no ransomware association is documented. EPSS shows a high 30-day probability (0.683, 99.3rd percentile), but the references are only vendor advisories and mailing list posts, with no public exploit code or in-the-wild confirmation stated.

What to do

  • Upgrade or patch imapd beyond version 4.7 per the vendor advisory; treat 4.7 as affected.
  • If patching is not immediately possible, restrict IMAP access to trusted networks and disable or limit untrusted accounts.
  • Enforce strong authentication and monitor for anomalous account use, since exploitation requires a valid account.
  • Consider running the IMAP service under a low-privilege account and with OS-level sandboxing to limit command execution impact.

Detection

  • Monitor IMAP server logs for malformed or unusually long LIST commands and other command arguments.
  • Alert on unexpected child processes or shell activity spawned by the imapd process.
  • Baseline normal IMAP session behavior per account and flag sessions issuing abnormal command sequences or volumes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-0284 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2000-0284), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.