Vulnerability Description
Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in SMTP requests.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Webeasymail | Webeasymail | <= 3.4.2.2 |
References
- http://online.securityfocus.com/archive/1/288222ExploitVendor Advisory
- http://www.iss.net/security_center/static/9924.phpVendor Advisory
- http://www.securityfocus.com/bid/5518Vendor Advisory
- http://online.securityfocus.com/archive/1/288222ExploitVendor Advisory
- http://www.iss.net/security_center/static/9924.phpVendor Advisory
- http://www.securityfocus.com/bid/5518Vendor Advisory
FAQ
What is CVE-2002-1415?
CVE-2002-1415 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Format string vulnerability in SMTP service for WebEasyMail 3.4.2.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in S...
How severe is CVE-2002-1415?
CVE-2002-1415 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2002-1415?
Check the references section above for vendor advisories and patch information. Affected products include: Webeasymail Webeasymail.