Lucene search

K
cve[email protected]CVE-2004-2677
HistoryFeb 22, 2007 - 10:00 p.m.

CVE-2004-2677

2007-02-2222:00:00
web.nvd.nist.gov
21
cve-2004-2677
format string vulnerability
qwikmail smtp
remote code execution
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.251 Low

EPSS

Percentile

96.7%

Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

Affected configurations

NVD
Node
qwikmailqwikmail_smtpMatch0.3

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

8.2 High

AI Score

Confidence

Low

0.251 Low

EPSS

Percentile

96.7%

Related for CVE-2004-2677