CVE detail
CVE-2001-1009 — CVE-2001-1009
Published 2001-08-31 · Modified 2026-06-16 · Vendor fetchmail · Product fetchmail · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0652
EPSS probability
exploitation probability, 30d
93.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Fetchmail (aka fetchmail-ssl) before 5.8.17 allows a remote malicious (1) IMAP server or (2) POP/POP3 server to overwrite arbitrary memory and possibly gain privileges via a negative index number as part of a response to a LIST request.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References