VulnerabilityModified
CVE-2003-1452
Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.
LOW 3.6EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.
- CVSS 2.0
- 3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 0.52% probability · 43th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- qualcomm/qpopper
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0047.htmlExploit
- http://securityreason.com/securityalert/3268
- http://www.securityfocus.com/archive/1/319811Exploit
- http://www.securityfocus.com/bid/7447Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11877
- http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0047.htmlExploit
- http://securityreason.com/securityalert/3268
- http://www.securityfocus.com/archive/1/319811Exploit
- http://www.securityfocus.com/bid/7447Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11877
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.