CVE-2014-0469: Debian Xbuffy

Medium severity, CVSS 6.8. EPSS: 3.4% chance of exploitation in the next 30 days.

Stack-based buffer overflow in a certain Debian patch for xbuffy before 3.3.bl.3.dfsg-9 allows remote attackers to execute arbitrary code via the subject of an email, possibly related to indent subject lines.

Affected products

  • Debian Xbuffy: up to and including 3.3.bl.3.dfsg-8; version 3.2.1-1 only; version 3.2.1-2 only; version 3.2.1-3 only; version 3.2.1-4 only; version 3.3-1 only; …

Published 2014-05-05. Last modified 2026-06-17.