29 results (0.005 seconds)

CVSS: 9.8EPSS: 9%CPEs: 1EXPL: 2

13 Jan 2015 — Buffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long string in a UID command. Desdbordamiento de buffer en el servicio IMAPd en Qualcomm Eudora WorldMail 9.0.333.0 permite a atacantes remotos ejecutar código arbitrario a través de una cadena larga en un comando UID. • https://www.exploit-db.com/exploits/31694 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 9.8EPSS: 3%CPEs: 1EXPL: 1

11 Jun 2007 — Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command. Desbordamiento de búfer en Qualcomm Eudora 7.1.0.9 permite a atacantes con la intervención de usuarios en servidores remotos IMAP ejecutar código de su elección a través de respuestas largas FLAGS en un comando SELECT INBOX. • https://www.exploit-db.com/exploits/4014 •

CVSS: 9.8EPSS: 4%CPEs: 1EXPL: 1

21 May 2007 — Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue. Desbordamiento de búfer basado en pila en Eudora 7.1 permite a servidores remotos SMTP con la intervención del usuario, ejcutar código de su elección a través de respuesta SMTP largas. NOTA: el usuario debería hacer click a través de un aviso sobre un posible desbordamie... • https://www.exploit-db.com/exploits/3934 •

CVSS: 9.8EPSS: 0%CPEs: 1EXPL: 0

21 Nov 2006 — Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack. NOTE: Some of these details are obtained from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for track... • http://secunia.com/advisories/22832 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 7.5EPSS: 0%CPEs: 1EXPL: 0

21 Nov 2006 — QUALCOMM Eudora WorldMail 4.0 allows remote attackers to cause a denial of service, as demonstrated by a certain module in VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. QUALCOMM Eudora WorldMail 4.0 permite a atacantes remotos ... • http://secunia.com/advisories/22836 • CWE-400: Uncontrolled Resource Consumption •

CVSS: 9.8EPSS: 3%CPEs: 1EXPL: 1

10 Feb 2006 — Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267. • https://www.exploit-db.com/exploits/1380 •

CVSS: 7.5EPSS: 3%CPEs: 1EXPL: 1

31 Dec 2004 — Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers. • https://www.exploit-db.com/exploits/163 •

CVSS: 7.5EPSS: 0%CPEs: 20EXPL: 0

31 Dec 2004 — Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow. • http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt •

CVSS: 9.8EPSS: 8%CPEs: 5EXPL: 2

06 May 2004 — Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name. • https://www.exploit-db.com/exploits/24096 •

CVSS: 7.5EPSS: 3%CPEs: 2EXPL: 3

14 Apr 2004 — Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message. • https://www.exploit-db.com/exploits/24000 •