peter bassill · operator
$ cve CVE-2001-0365 JSON

CVE-2001-0365 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 3.2% (pctl 88)

Patch early

A public exploit exists.

Description

Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email message containing Javascript, with ActiveX controls and malicious code within IMG tags.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS3.19% — more likely to be exploited than 88% of all CVEs
On CISA KEVno
Public exploityes
Published2001-06-27
Last modified2026-06-16

Affected (1)

VendorProduct
qualcommeudora

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD