CVE-2003-1266 describes a denial-of-service vulnerability affecting EServer versions 2.92 through 2.97, and potentially 2.98, where remote attackers can crash the FTP, POP3, SMTP, and NNTP servers by sending an excessive amount of data. This vulnerability has a CVSS score of 5.0, indicating a network-based attack with low complexity and no authentication required, leading to a partial availability impact. While not listed in CISA KEV, exploit code is publicly available on ExploitDB for all affected services, and the CVE has garnered significant community discussion, suggesting awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.92CPE matchmatch criteria | cpe:2.3:a:etype:eserv:2.92:*:*:*:*:*:*:* | ||
2.93CPE matchmatch criteria | cpe:2.3:a:etype:eserv:2.93:*:*:*:*:*:*:* | ||
2.94CPE matchmatch criteria | cpe:2.3:a:etype:eserv:2.94:*:*:*:*:*:*:* | ||
2.95CPE matchmatch criteria | cpe:2.3:a:etype:eserv:2.95:*:*:*:*:*:*:* | ||
2.96CPE matchmatch criteria | cpe:2.3:a:etype:eserv:2.96:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.