← Browse

CVE-2004-2771

Medium

Elevated severity or exploit probability.

CVSS base
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS — probability of exploitation (30 days)
6.9%
93.8th percentile
CISA KEV
Not listed
Weakness / dates
CWE-20
Published 2014-12-24 · modified 2026-09-23

Description

The expand function in fio.c in Heirloom mailx 12.5 and earlier and BSD mailx 8.1.2 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an email address.

Affected

bsd_mailx_project heirloom oracle redhat

References

Official: NVD · CVE.org