CyberSec.Space Logo
返回 CVE 浏览器

CVE-2003-0143

CRITICAL
10.0
CVSS Severity Score
EPSS Score0.1430%
EPSS Percentile6.19th
Published2003年3月18日
Last Modified2026年4月16日

Vulnerability Description

The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.

Affected Platforms (CPE)

📦
Qualcomm

Qpopper

= 4.0.1
📦
Qualcomm

Qpopper

= 4.0.2
📦
Qualcomm

Qpopper

= 4.0.3
📦
Qualcomm

Qpopper

= 4.0.4

References & Advisories

相关漏洞威胁