7.5
CVSSv2

CVE-2006-0637

Published: 10/02/2006 Updated: 19/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote malicious users to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267.

Vulnerable Product Search on Vulmon Subscribe to Product

qualcomm eudora worldmail 3.0

Exploits

#!/usr/bin/python ################################################################################### # # PRE AUTHENTICATION Eudora Qualcomm WorldMail 30 IMAPd Service 61190 Overflow # # Discovered by Tim Shelton - security-advisories@acs-inccom # # Coded by mati@see-securitycom # # Details: # * SEH gets overwritten at 970 bytes in the LIST ...