Qualcomm
Qualcomm Qpopper: vulnerabilidades y CVE
Qualcomm Qpopper tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2005-3098 | Media (4.6) | 0.58% | — | 28 sept 2005 | poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument. |
| CVE-2003-1452 | Baja (3.6) | 0.52% | — | 31 dic 2003 | Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program. |
| CVE-2003-0143 | Alta (10) | 8.6% | — | 18 mar 2003 | The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef… |
| CVE-2002-0889 | Media (4.6) | 0.29% | — | 4 oct 2002 | Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file. |
| CVE-2002-0454 | Media (5) | 5.2% | — | 12 ago 2002 | Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop. |
| CVE-2001-1487 | Media (4.6) | 0.52% | — | 31 dic 2001 | popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option. |
| CVE-2001-1068 | Media (5) | 1.1% | — | 31 ago 2001 | qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames… |
| CVE-2000-1198 | Media (5.5) | 0.35% | — | 31 ago 2001 | qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. |
| CVE-2001-1046 | Alta (10) | 1.9% | — | 2 jun 2001 | Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username. |
| CVE-2000-0442 | Alta (7.5) | 3.3% | — | 24 may 2000 | Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command. |
| CVE-2000-0320 | Media (5) | 1.2% | — | 21 abr 2000 | Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023… |
| CVE-2000-0096 | Alta (7.2) | 0.51% | — | 26 ene 2000 | Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command. |
| CVE-1999-0822 | Alta (10) | 4.9% | — | 30 nov 1999 | Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. |
| CVE-1999-0006 | Crítica (9.8) | 12% | — | 14 jul 1998 | Buffer overflow in POP servers based on BSD/Qualcomm's qpopper allows remote attackers to gain root access using a long PASS command. |