peter bassill · operator
$ cve CVE-2004-2677 JSON

CVE-2004-2677 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 6.5% (pctl 94)

Patch early

A public exploit exists.

Description

Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS6.48% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploityes
Published2004-12-31
Last modified2026-06-16

Affected (1)

VendorProduct
qwikmailqwikmail smtp

Public exploits

SourceTitleDate
exploit-dbQwik SMTP 0.3 - Format String2004-11-09

References

→ the Explorer  ·  watch your stack  ·  NVD