peter bassill · operator
$ cve CVE-2003-0143 JSON

CVE-2003-0143 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 8.6% (pctl 95)

Patch early

A public exploit exists.

Description

The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS8.6% — more likely to be exploited than 95% of all CVEs
On CISA KEVno
Public exploityes
Published2003-03-18
Last modified2026-06-16

Affected (1)

VendorProduct
qualcommqpopper

Public exploits

SourceTitleDate
exploit-dbQpopper 4.0.x - Remote Memory Corruption2003-03-10

References

→ the Explorer  ·  watch your stack  ·  NVD