Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Nico

#18419of 53,624
14.7Total CVSS
Vulnerabilities · 2
High
2
PT-2005-4955
7.5
2005-12-21
Qualcomm · Qualcomm Worldmail · CVE-2005-4267
**Name of the Vulnerable Software and Affected Versions** Qualcomm WorldMail version 3.0 **Description** A stack-based buffer overflow issue allows remote attackers to execute arbitrary code via a long IMAP command that ends with a "}" character. This can be achieved using various IMAP commands, including "LIST", "LSUB", "SEARCH TEXT", "STATUS INBOX", "AUTHENTICATE", "FETCH", "SELECT", and "COPY". **Recommendations** For Qualcomm WorldMail version 3.0, consider restricting the length of IMAP commands to prevent buffer overflow exploitation until a patch is available. As a temporary workaround, limit the use of IMAP commands that could be used to trigger the overflow, such as avoiding the use of long commands that end with a "}" character. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2005-1642
7.2
2005-05-04
Netinfo · Netinfo Setup Tool · CVE-2005-0594
**Name of the Vulnerable Software and Affected Versions** Netinfo Setup Tool (NeST) (affected versions not specified) **Description** A buffer overflow issue in the Netinfo Setup Tool (NeST) allows local users to execute arbitrary code. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.