Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to execute arbitrary code via format string specifiers in the SEARCH command.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.571
EPSS Ranking 98.0%