CVE-2006-6024
Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.98%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in Eudora Worldmail, possibly Worldmail 3 version 6.1.22.0, have unknown impact and attack vectors, as demonstrated by the (1) "Eudora WorldMail stack overflow" and (2) "Eudora WorldMail heap overflow" modules in VulnDisco Pack. NOTE: Some of these details are obtained from third party information. As of 20061118, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- qualcomm/eudora worldmail
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/22832Vendor Advisory
- http://web.archive.org/web/20060502082657/http://www.gleg.net/vulndisco_pack_standard.shtml
- http://www.securityfocus.com/bid/21095
- http://secunia.com/advisories/22832Vendor Advisory
- http://web.archive.org/web/20060502082657/http://www.gleg.net/vulndisco_pack_standard.shtml
- http://www.securityfocus.com/bid/21095
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.