peter bassill · operator
$ cve CVE-2006-0637 JSON

CVE-2006-0637 EXPLOIT

7.5
HIGH · CVSS 2.0 · EPSS 2.1% (pctl 82)

Patch early

A public exploit exists.

Description

Buffer overflow in cram.dll in QUALCOMM Eudora WorldMail 3.0 allows remote attackers to execute arbitrary code via an IMAP APPEND command with a long message literal argument, as demonstrated by Worldmail.pl. NOTE: this is a different vector and a different manipulation than CVE-2005-4267, so it might be a different vulnerability than CVE-2005-4267.

Scoring

CVSS7.5 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS2.14% — more likely to be exploited than 82% of all CVEs
On CISA KEVno
Public exploityes
Published2006-02-10
Last modified2026-06-16

Affected (1)

VendorProduct
qualcommeudora worldmail

Public exploits

SourceTitleDate
exploit-dbEudora Qualcomm WorldMail 3.0 - 'IMAPd' Remote Overflow2005-12-20

References

→ the Explorer  ·  watch your stack  ·  NVD