CVE detail
CVE-2005-2431 — CVE-2005-2431
Published 2005-08-03 · Modified 2026-06-16 · Vendor gforge · Product gforge · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0133
EPSS probability
exploitation probability, 30d
68.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The (1) lost password and (2) account pending features in GForge 4.5 do not properly set a limit on the number of e-mails sent to an e-mail address, which allows remote attackers to send a large number of messages to arbitrary e-mail addresses (aka mail bomb).
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References