cbcvebase.

Qualcomm Qpopper vulnerabilities

14 known vulnerabilities affecting qualcomm/qpopper.

Total CVEs
14
CISA KEV
0
Public exploits
10
Exploited in wild
0
Severity breakdown
CRITICAL4HIGH2MEDIUM7LOW1

Vulnerabilities

Page 1 of 1
CVE-1999-0006P3CRITICALCVSS 9.8PoCv2.41998-07-14
CVE-1999-0006 [CRITICAL] CWE-125 CVE-1999-0006: Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command.
nvd
CVE-1999-0822P3CRITICALCVSS 10.0PoCv3.0v3.0b201999-11-30
CVE-1999-0822 [CRITICAL] CVE-1999-0822: Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command.
nvd
CVE-2003-0143P3CRITICALCVSS 10.0PoCv4.0.1v4.0.2+2 more2003-03-18
CVE-2003-0143 [CRITICAL] CVE-2003-0143: The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.
nvd
CVE-2000-0442P4HIGHCVSS 7.5PoCv2.52v2.532000-05-24
CVE-2000-0442 [HIGH] CVE-2000-0442: Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
nvd
CVE-2000-0096P4HIGHCVSS 7.2PoCv3.0v3.0beta1+28 more2000-01-26
CVE-2000-0096 [HIGH] CVE-2000-0096: Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST c Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command.
nvd
CVE-2005-3098P4MEDIUMCVSS 4.6PoCv4.0.82005-09-28
CVE-2005-3098 [MEDIUM] CVE-2005-3098: poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.
nvd
CVE-2002-0454P4MEDIUMCVSS 5.0PoCv4.0v4.0.1+2 more2002-08-12
CVE-2002-0454 [MEDIUM] CVE-2002-0454: Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of se Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.
nvd
CVE-2001-1046P3CRITICALCVSS 10.0v4.0v4.0.1+1 more2001-06-02
CVE-2001-1046 [CRITICAL] CVE-2001-1046: Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain pr Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
nvd
CVE-2001-1487P4MEDIUMCVSS 4.6PoC≤ 4.02001-12-31
CVE-2001-1487 [MEDIUM] CVE-2001-1487: popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.
nvd
CVE-2003-1452P4LOWCVSS 3.6PoCv4.0v4.0.1+6 more2003-12-31
CVE-2003-1452 [LOW] CWE-16 CVE-2003-1452: Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execu Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.
nvd
CVE-2000-1198P4MEDIUMCVSS 5.5PoCv2.53v3.02001-08-31
CVE-2000-1198 [MEDIUM] CWE-667 CVE-2000-1198: qpopper POP server creates lock files with predictable names, which allows local users to cause a de qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
nvd
CVE-2001-1068P4MEDIUMCVSS 5.0v4.0.12001-08-31
CVE-2001-1068 [MEDIUM] CVE-2001-1068: qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages whe qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.
nvd
CVE-2002-0889P4MEDIUMCVSS 4.6v4.0.3v4.0.42002-10-04
CVE-2002-0889 [MEDIUM] CVE-2002-0889: Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of servic Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file.
nvd
CVE-2000-0320P4MEDIUMCVSS 5.0v2.53v3.02000-04-21
CVE-2000-0320 [MEDIUM] CVE-2000-0320: Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message te Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n.
nvd
Qualcomm Qpopper vulnerabilities | cvebase