An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
CVE ID: CVE-2024-4140
CVSS Base Severity: HIGH
CVSS Base Score: 7.5
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vendor: rjbs
Product: Email-MIME
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 16.97% (scored less or equal to compared to others)
EPSS Date: 2025-03-14 (when was this score calculated)