CVE-2004-1013

CRITICAL

The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[...

Affects 6 products across 6 vendors.

BCS7.86
CVSS 2.010.0
EPSS5.8%
Percentile92th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

This vulnerability was disclosed in 2005. A critical vulnerability affects Carnegie Mellon University systems (CVE-2004-1013). No public exploit code is currently available. Isolate affected systems if patching is not feasible.

BSID: BS-2005-GLOBAL-008250-C • Model: rule-based-v1 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-1013?
This vulnerability was disclosed in 2005. A critical vulnerability affects Carnegie Mellon University systems (CVE-2004-1013). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
What is the CVSS score for CVE-2004-1013?
CVE-2004-1013 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 5.8%.
Is CVE-2004-1013 actively exploited?
No confirmed active exploitation of CVE-2004-1013 as of 2026-05-30.
How do I remediate CVE-2004-1013?
Priority: MEDIUM. Advisory: http://www.debian.org/security/2004/dsa-597 PSIRT: [email protected]
What systems are affected by CVE-2004-1013?
CVE-2004-1013 affects: Carnegie Mellon University, Conectiva, Openpkg, Redhat, Trustix, Ubuntu.
Vulnerability Details
CVE IDCVE-2004-1013
BSIDBS-2005-GLOBAL-008250-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2005-01-10
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

Vulnerability details: The argument parser of the FETCH command in Cyrus IMAP Server 2.2.x through 2.2.8 allows remote authenticated users to execute arbitrary code via certain commands such as (1) "body[p", (2) "binary[p", or (3) "binary[p") that cause an index increment error that leads to an out-of-bounds memory corruption. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.

Exploitation Likelihood: LOW

Affected Products
VendorProductFixed Version
Carnegie Mellon University Cyrus Imap Server
Conectiva Linux
Openpkg Openpkg
Redhat Fedora Core
Trustix Secure Linux
Ubuntu Ubuntu Linux
Remediation
View Vendor Advisory →

Remediation Priority: MEDIUM

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 7853 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Modelrule-based-v1
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hashe89ae3b945c1937aeb7d1cd6e5eec6b0cd5bbf3cbb69d2ae22902f2b7a61c3d63db4ac499694be9c7102823968ad2e9a8ce63d18dfa8e6d05415d746579f44df
Related CVEs affecting Carnegie Mellon University
CVE-2004-1012 10.0 The argument parser of the PARTIAL command in Cyrus IMAP Server 2.2.6 and ear... CVE-2004-1015 10.0 Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the i... CVE-2004-1067 10.0 Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9... CVE-2004-1011 10.0 Stack-based buffer overflow in Cyrus IMAP Server 2.2.4 through 2.2.8, with th... CVE-2009-0688 7.5 Multiple buffer overflows in the CMU Cyrus SASL library before 2.1.23 might a...
View all Carnegie Mellon University CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →