
CVE-2006-6024
https://notcve.org/view.php?id=CVE-2006-6024
21 Nov 2006 — Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack. NOTE: Some of these details are obtained from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for track... • http://secunia.com/advisories/22832 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVE-2006-0637 – Eudora Qualcomm WorldMail 3.0 - 'IMAPd' Remote Overflow
https://notcve.org/view.php?id=CVE-2006-0637
10 Feb 2006 — Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267. • https://www.exploit-db.com/exploits/1380 •

CVE-2004-2301
https://notcve.org/view.php?id=CVE-2004-2301
31 Dec 2004 — Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow. • http://www.eudora.com/download/eudora/windows/6.1.1/RelNotes.txt •

CVE-2001-0365 – Qualcomm Eudora 5.0.2 - 'Use Microsoft Viewer' Code Execution
https://notcve.org/view.php?id=CVE-2001-0365
27 Jun 2001 — Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags. • https://www.exploit-db.com/exploits/20688 •

CVE-1999-0427
https://notcve.org/view.php?id=CVE-1999-0427
04 Feb 2000 — Eudora 4.1 allows remote attackers to perform a denial of service by sending attachments with long file names. • https://exchange.xforce.ibmcloud.com/vulnerabilities/CVE-1999-0427 •

CVE-1999-1448
https://notcve.org/view.php?id=CVE-1999-1448
29 Jul 1998 — Eudora and Eudora Light before 3.05 allows remote attackers to cause a crash and corrupt the user's mailbox via an e-mail message with certain dates, such as (1) dates before 1970, which cause a Divide By Zero error, or (2) dates that are 100 years after the current date, which causes a segmentation fault. • http://marc.info/?l=bugtraq&m=90221104526168&w=2 •