CVE-2004-0510 describes multiple buffer overflows in the MMDF mail transfer agent, specifically affecting SCO OpenServer versions 5.0.6 and 5.0.7. This vulnerability allows an attacker to execute arbitrary code with elevated privileges, as demonstrated through the execmail program. With a CVSS score of 7.2 (AV:L/AC:L/Au:N/C:C/I:C/A:C), it represents a high-severity local attack requiring low complexity, leading to complete compromise of confidentiality, integrity, and availability. While not currently on the CISA KEV catalog or Hot List, an exploit for privilege escalation via MMDF deliver is publicly available on ExploitDB, and the CVE has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0.6CPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.6:*:*:*:*:*:*:* | ||
5.0.6aCPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.6a:*:*:*:*:*:*:* | ||
5.0.7CPE matchmatch criteria | cpe:2.3:o:sco:openserver:5.0.7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.