Vulnerabilities > Qualcomm > Qpopper

DATE CVE VULNERABILITY TITLE RISK
2005-09-28 CVE-2005-3098 Local Arbitrary File Modification vulnerability in Qualcomm Qpopper 4.0.8
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace file) command line argument.
local
low complexity
qualcomm
4.6
2003-12-31 CVE-2003-1452 Configuration vulnerability in Qualcomm Qpopper
Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.
local
low complexity
qualcomm CWE-16
3.6
2003-03-18 CVE-2003-0143 Remote Memory Corruption vulnerability in Qpopper
The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.
network
low complexity
qualcomm
critical
10.0
2002-10-04 CVE-2002-0889 Buffer Overflow vulnerability in Qualcomm QPopper Bulletin Name
Buffer overflow in Qpopper (popper) 4.0.4 and earlier allows local users to cause a denial of service and possibly execute arbitrary code via a long bulldir argument in the user's .qpopper-options configuration file.
local
low complexity
qualcomm
4.6
2002-08-12 CVE-2002-0454 Remote Denial of Service vulnerability in Qualcomm QPopper
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a very large string, which causes an infinite loop.
network
low complexity
qualcomm
5.0
2001-12-31 CVE-2001-1487 Local Security vulnerability in qpopper
popauth utility in Qualcomm Qpopper 4.0 and earlier allows local users to overwrite arbitrary files and execute commands as the pop user via a symlink attack on the -trace file option.
local
low complexity
qualcomm
4.6
2001-08-31 CVE-2001-1068 Unspecified vulnerability in Qualcomm Qpopper 4.0.1
qpopper 4.01 with PAM based authentication on Red Hat systems generates different error messages when an invalid username is provided instead of a valid name, which allows remote attackers to determine valid usernames on the system.
network
low complexity
qualcomm
5.0
2001-08-31 CVE-2000-1198 Improper Locking vulnerability in Qualcomm Qpopper 2.53/3.0
qpopper POP server creates lock files with predictable names, which allows local users to cause a denial of service for other users (lack of mail access) by creating lock files for other mail boxes.
local
low complexity
qualcomm CWE-667
5.5
2001-06-02 CVE-2001-1046 Buffer Overflow vulnerability in Qualcomm Qpopper 4.0/4.0.1/4.0.2
Buffer overflow in qpopper (aka qpop or popper) 4.0 through 4.0.2 allows remote attackers to gain privileges via a long username.
network
low complexity
qualcomm
critical
10.0
2000-05-24 CVE-2000-0442 Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is processed by the euidl command.
network
low complexity
qualcomm sun
7.5