CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option. | 4.6 |
|||
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes. | 5.5 |
Medium |
||
Qpopper 2.53 and 3.0 does not properly identify the \n string which identifies the end of message text, which allows a remote attacker to cause a denial of service or corrupt mailboxes via a message line that is 1023 characters long and ends in \n. | 5 |
|||
Buffer overflow in qpopper 3.0 beta versions allows local users to gain privileges via a long LIST command. | 7.2 |
|||
Buffer overflow in Qpopper (qpop) 3.0 allows remote root access via AUTH command. | 10 |