📦

eudora

Vendor: eudora

Actively Exploited 0 CISA KEV List
PoC / Exploits 14 Code Available
Total RCEs 11 Remote Access
Total CVEs 1 Total Indexed
Avg. EPSS 3.75% Exploit Prob.
Latest CVE CVE-2007-3166 Jun 11

Security Vulnerability Index

Page 1 / 1
6.8 CVSS
CVE-2007-3166
RCE Exploit Found

Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command.

EPSS: 3.23%
9.3 CVSS
CVE-2007-2770
RCE Exploit Found

Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning about a possible buffer overflow exploit to trigger this issue.

EPSS: 3.77%
5.0 CVSS

Eudora before 6.1.1 allows remote attackers to cause a denial of service (crash) via an e-mail with a long "To:" field, possibly due to a buffer overflow.

EPSS: 0.81%
5.8 CVSS
CVE-2004-2649
Exploit Found

Eudora 6.1.0.6 allows remote attackers to obfuscate URLs displayed in the status bar by inserting a large number of characters (e.g. spaces coded as "&#32") in the middle of the URL.

EPSS: 8.93%
5.0 CVSS
CVE-2004-1521
Exploit Found

Eudora 6.2.0.14 does not issue a warning when a user forwards an e-mail message that contains base64 or quoted-printable encoded attachments, which makes it easier for remote attackers to read arbitrary files via spoofed "Converted" headers.

EPSS: 3.45%
5.1 CVSS
CVE-2004-2005
Exploit Found

Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a long attachment name.

EPSS: 20.82%
5.0 CVSS
CVE-2004-1944
Exploit Found

Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.

EPSS: 3.92%
5.0 CVSS

The IMAP Client for Eudora 5.2.1 allows remote malicious IMAP servers to cause a denial of service and possibly execute arbitrary code via certain large literal size values that cause either integer signedness errors or integer overflow errors.

EPSS: 0.86%
5.0 CVSS

The IMAP Client for Sylpheed 0.8.11 allows remote malicious IMAP servers to cause a denial of service (crash) via certain large literal size values that cause either integer signedness errors or integer overflow errors.

EPSS: 0.84%
5.0 CVSS
CVE-2003-0376
RCE Exploit Found

Buffer overflow in Eudora 5.2.1 allows remote attackers to cause a denial of service (crash and failed restart) and possibly execute arbitrary code via an Attachment Converted argument with a large number of . (dot) characters.

EPSS: 9.43%