Vulnerability Details CVE-2005-2655
lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.7%
CVSS Severity
CVSS v2 Score 10.0
Products affected by CVE-2005-2655
-
cpe:2.3:a:maildrop:maildrop:0.50
-
cpe:2.3:a:maildrop:maildrop:0.51
-
cpe:2.3:a:maildrop:maildrop:0.51b
-
cpe:2.3:a:maildrop:maildrop:0.51c
-
cpe:2.3:a:maildrop:maildrop:0.54
-
cpe:2.3:a:maildrop:maildrop:0.54a
-
cpe:2.3:a:maildrop:maildrop:0.54b
-
cpe:2.3:a:maildrop:maildrop:0.55
-
cpe:2.3:a:maildrop:maildrop:0.55a
-
cpe:2.3:a:maildrop:maildrop:0.55b
-
cpe:2.3:a:maildrop:maildrop:0.55c
-
cpe:2.3:a:maildrop:maildrop:0.60
-
cpe:2.3:a:maildrop:maildrop:0.61
-
cpe:2.3:a:maildrop:maildrop:0.62
-
cpe:2.3:a:maildrop:maildrop:0.63
-
cpe:2.3:a:maildrop:maildrop:0.64
-
cpe:2.3:a:maildrop:maildrop:0.65
-
cpe:2.3:a:maildrop:maildrop:0.70
-
cpe:2.3:a:maildrop:maildrop:0.71
-
cpe:2.3:a:maildrop:maildrop:0.72
-
cpe:2.3:a:maildrop:maildrop:0.73
-
cpe:2.3:a:maildrop:maildrop:0.74
-
cpe:2.3:a:maildrop:maildrop:0.75
-
cpe:2.3:a:maildrop:maildrop:0.76
-
cpe:2.3:a:maildrop:maildrop:0.99.1
-
cpe:2.3:a:maildrop:maildrop:0.99.2
-
cpe:2.3:a:maildrop:maildrop:1.0
-
cpe:2.3:a:maildrop:maildrop:1.1
-
cpe:2.3:a:maildrop:maildrop:1.2
-
cpe:2.3:a:maildrop:maildrop:1.2.1
-
cpe:2.3:a:maildrop:maildrop:1.2.2
-
cpe:2.3:a:maildrop:maildrop:1.3.0
-
cpe:2.3:a:maildrop:maildrop:1.3.1
-
cpe:2.3:a:maildrop:maildrop:1.3.3
-
cpe:2.3:a:maildrop:maildrop:1.3.4
-
cpe:2.3:a:maildrop:maildrop:1.3.5
-
cpe:2.3:a:maildrop:maildrop:1.3.6
-
cpe:2.3:a:maildrop:maildrop:1.3.7
-
cpe:2.3:a:maildrop:maildrop:1.3.8
-
cpe:2.3:a:maildrop:maildrop:1.3.9
-
cpe:2.3:a:maildrop:maildrop:1.4.0
-
cpe:2.3:a:maildrop:maildrop:1.5.0
-
cpe:2.3:a:maildrop:maildrop:1.5.1
-
cpe:2.3:a:maildrop:maildrop:1.5.2