« Volver al listado

CVE-2008-3606

Estado: ModificadaMedia (6.5)—

Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-3606",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-08-12T19:41:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/31442",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4146",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/495264/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/30606",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1020644",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44370",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/31442",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/4146",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/495264/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/30606",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1020644",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44370",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command.  NOTE: some of these details are obtained from third party information."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer basado en montículo en en el servicio IMAP en Qbik WinGate 6.2.2.1137 y anteriores, permiten a atacantes remotos autenticados provocar una denegación de servicio (agotamiento de recursos) o posiblemente, ejecución de código arbitrario a través de un argumento largo en el comando LIST. NOTA: algunos de estos detalles se han obtenido a partir de información de terceros."
    }
  ],
  "lastModified": "2026-06-16T22:56:08.307",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:qbik:wingate:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D592FD10-CC88-46CD-A726-EEC5191DE725",
              "versionEndIncluding": "6.2.2"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7B534B6E-B856-4E7F-A8E0-582637EE6B30"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA8E8CEE-E78A-46D5-B73D-C75CC8D088B5"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C7BC4C8-FB7B-4A88-B97B-984D9AA8EA1D"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:3.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "87714896-157D-4343-A94F-C8CCAD285EEA"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C1D98E1-EBE1-4697-906F-E29C91D9074D"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.1:beta_a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "077D0405-5288-40A6-81A8-A8C4D924723D"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE28B657-21EE-4F2E-8D1F-34D4E2642BE6"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EDB73A60-062E-4A0B-B600-E1B4D613FE28"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F0BB2B5-9E9A-42FC-87A4-0BAD1F39C9FD"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA75B20B-3510-4CF9-A74B-BA21D5527EE4"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.3.0:beta_a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F54C4B69-397F-4322-A1AD-11AF2C7F5F67"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.3.0:beta_b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "076063FF-B1D2-471D-ACDD-0AF3BA328069"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.4.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5B1AE22-2A99-4F4B-AAF6-6CBF35FEAEE7"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.4.0:beta_a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57726A67-AFC8-44E0-88D7-CA1C1DFA7C81"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49897B9F-9A10-4034-B617-1B82405FB1E2"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.4.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D8109BA-2FFF-4642-AD15-FA11CD3088AA"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.5.0:beta_a:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E56752EB-E1F5-4132-B769-33633E1B67FE"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.5.0:beta_b:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "49465E28-E5CD-4533-8A01-8BBE868F2AD3"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "59FE243C-16F2-4C6D-BF88-FFB6CD0F29BF"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:4.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE5A4F3B-B855-4980-93D9-347A49E68EE6"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0AFAF415-0182-4F5C-A053-266AB919572F"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10D7B35B-3531-4372-A338-AD8106799769"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3712DA96-DD76-49E3-BA79-30105725DBD7"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.0.1.766:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F912B8D6-B915-43A7-8462-F521D44DBD1C"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40A0AE5B-B449-4494-828E-2FD7414F6FD1"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "109DF494-0194-473B-AF79-185D41202A8E"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "39B77B55-54BB-43D5-A0E9-13F20F7544F1"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36B7A6B3-8C54-4743-8C42-6B22E9AD719B"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:5.2.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E328107F-F19D-427D-A88A-17DCB58A459C"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E3F0670C-C07E-4A84-952B-88200D2D9B14"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.0.984:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E8E6305C-F87B-4DF1-94D7-A0C63EE11E7A"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.1.993:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8EE5BB2B-F9CB-4CDA-9CC9-C6EF5A1FF59F"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.1.995:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A480A0D4-D675-4078-8F30-CD3772818303"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.2.1000:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F9B03DEA-B780-404E-B940-82A7086062C5"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.2.1001:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B5CA5961-6BAC-4BE8-95A4-DBEB0596262E"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.3.1005:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ED850FD8-151C-49E7-9DF4-16B88341269B"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.0.4.1025:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A406438F-7E92-4579-A32B-3E3E1C4FF8E5"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.1.1.1077:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9FDF759C-0AAE-4760-B829-13F055AD290C"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.1.2.1094:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "982DE691-B50E-49B2-B4DF-EC518DFFCE75"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.1.3.1096:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F8EFCA3-2453-4272-9692-22598676DFC0"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.1.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1F5F3CDE-1931-4BD9-9ABD-F07543DAC113"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C1E8C06-4E84-4FB8-A513-D8ACC1146BEF"
            },
            {
              "criteria": "cpe:2.3:a:qbik:wingate:6.2.2.1137:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0C45F717-AC74-4F81-947B-0745A7F1883F"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}