LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

CVE DATABASE  /  CVE-2005-4080

CVE-2005-4080

CVSS 4.3 · MEDIUM

Summary

Horde IMP 4.0.4 and earlier does not sanitize strings containing UTF16 null characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via UTF16 encoded attachments and strings that will be executed when viewed using Internet Explorer, which ignores the characters.

CVSS 2.0 breakdown

Base score4.3 (MEDIUM)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Attack vectorNETWORK
Attack complexityMEDIUM
ConfidentialityNONE
IntegrityPARTIAL
AvailabilityNONE

Affected products

Horde imp
Check this CVE live

Use our free CVE Lookup tool for the latest NVD record, or browse the full CISA KEV catalog.

References

Data: NIST NVD. NVD last modified 2026-04-16. Always verify against the vendor advisory before acting.

Scroll to Top