CVE-2003-0280 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 14.7% (pctl 97)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in the SMTP Service for ESMTP CMailServer 4.0.2003.03.27 allow remote attackers to execute arbitrary code via long (1) MAIL FROM or (2) RCPT TO commands.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 14.75% — more likely to be exploited than 97% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2003-06-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| youngzsoft | cmailserver |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Youngzsoft CMailServer 4.0 - MAIL FROM Buffer Overflow | 2003-05-10 |
| exploit-db | Youngzsoft CMailServer 4.0 - 'RCPT TO' Buffer Overflow | 2003-05-10 |
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html
- http://marc.info/?l=bugtraq&m=105258772101349&w=2
- http://www.securityfocus.com/bid/7547
- http://www.securityfocus.com/bid/7548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11975
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0062.html
- http://marc.info/?l=bugtraq&m=105258772101349&w=2
- http://www.securityfocus.com/bid/7547
- http://www.securityfocus.com/bid/7548
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11975
→ the Explorer · watch your stack · NVD