CVE-1999-0042
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Affects 6 products across 5 vendors.
A critical buffer overflow vulnerability exists in the University of Washington's implementation of IMAP and POP servers, which could allow an attacker to execute arbitrary code with the privileges of the server.
BSID: BS-1997-GLOBAL-159023-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-1999-0042?
What is the CVSS score for CVE-1999-0042?
Is CVE-1999-0042 actively exploited?
How do I remediate CVE-1999-0042?
What systems are affected by CVE-1999-0042?
| CVE ID | CVE-1999-0042 |
|---|---|
| BSID | BS-1997-GLOBAL-159023-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 1997-04-07 |
| Last Modified | 2026-04-16 |
| ICS Relevance | 0% |
| Source | NVD |
Buffer overflow in University of Washington's implementation of IMAP and POP servers.
Source: NIST NVD / MITRE CVE Database
The vulnerability is triggered by sending a specially crafted command to the IMAP or POP server, which can cause a buffer overflow. This can lead to a crash of the server or, more seriously, allow an attacker to execute arbitrary code.
Exploitation Likelihood: CRITICAL
| Vendor | Product | Fixed Version |
|---|---|---|
| Bsdi | Bsd Os | — |
| Caldera | Openlinux | — |
| Ibm | Aix | — |
| Redhat | Linux | — |
| University Of Washington | Imap | — |
| University Of Washington | Pop | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | ⚠ Available — Reference |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →