VendorsMetamail Corporationmetamailall versions
Vulnerabilities

Metamail Corporation Metamail

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2004-0104
Multiple format string vulnerabilities in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
Published 2004-02-19 · Modified
7.51 PoCEPSS 0.262
CVE-2004-0105
Multiple buffer overflows in Metamail 2.7 and earlier allow remote attackers to execute arbitrary code.
Published 2004-02-19 · Modified
7.5EPSS 0.082
CVE-2006-0709
Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via e-mail messages with a long boundary attribute, a different vulnerability than CVE-2004-0105.
Published 2006-02-15 · Modified
7.5EPSS 0.064
CVE-1999-1261
Buffer overflow in Rainbow Six Multiplayer allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long nickname (nick) command.
Published 2001-09-12 · Modified
5.0EPSS 0.016
CVE-1999-1266
rsh daemon (rshd) generates different error messages when a valid username is provided versus an invalid name, which allows remote attackers to determine valid users on the system.
Published 2001-09-12 · Modified
5.0EPSS 0.013
CVE-1999-1263
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
Published 2002-03-09 · Modified
2.6EPSS 0.010
CVE-2004-1808
Extcompose in metamail does not verify the output file before writing to it, which allows local users to overwrite arbitrary files via a symlink attack.
Published 2005-05-10 · Modified
2.1EPSS 0.003