Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2001-0365

4 documents4 sources
Severity
7.5HIGH
EPSS
4.8%
top 10.49%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJun 27
Latest updateApr 30

Description

Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages1 packages

NVDqualcomm/eudora5.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-p673-v55p-52j2: Eudora before 52022-04-30
CVEList
CVE-2001-0365: Eudora before 52002-03-09

💥Exploits & PoCs

1
Exploit-DB
Qualcomm Eudora 5.0.2 - 'Use Microsoft Viewer' Code Execution2001-03-18
CVE-2001-0365 (HIGH CVSS 7.5) | Eudora before 5.1 allows a remote a | cvebase.io