7.5
CVE-2003-0743
- EPSS 7.02%
- Veröffentlicht 20.10.2003 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Heap-based buffer overflow in smtp_in.c for Exim 3 (exim3) before 3.36 and Exim 4 (exim4) before 4.21 may allow remote attackers to execute arbitrary code via an invalid (1) HELO or (2) EHLO argument with a large number of spaces followed by a NULL character and a newline, which is not properly trimmed before the "(no argument given)" string is appended to the buffer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
University Of Cambridge ≫ Exim Version3.0
University Of Cambridge ≫ Exim Version3.3
University Of Cambridge ≫ Exim Version3.3.1
University Of Cambridge ≫ Exim Version3.3.2
University Of Cambridge ≫ Exim Version3.11
University Of Cambridge ≫ Exim Version3.12
University Of Cambridge ≫ Exim Version3.13
University Of Cambridge ≫ Exim Version3.14
University Of Cambridge ≫ Exim Version3.15
University Of Cambridge ≫ Exim Version3.16
University Of Cambridge ≫ Exim Version3.17
University Of Cambridge ≫ Exim Version3.18
University Of Cambridge ≫ Exim Version3.19
University Of Cambridge ≫ Exim Version3.20
University Of Cambridge ≫ Exim Version3.21
University Of Cambridge ≫ Exim Version3.22
University Of Cambridge ≫ Exim Version3.30
University Of Cambridge ≫ Exim Version3.31
University Of Cambridge ≫ Exim Version3.32
University Of Cambridge ≫ Exim Version3.33
University Of Cambridge ≫ Exim Version3.34
University Of Cambridge ≫ Exim Version3.35
University Of Cambridge ≫ Exim Version3.36
University Of Cambridge ≫ Exim Version4.10
University Of Cambridge ≫ Exim Version4.20
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 7.02% | 0.906 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|