CVE-2009-3837
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 32%
from disclosure to weapon0 days
Published on NVDNov 2
1st PoCOct 23
metasploitOct 22
exploitation probability
32%top 2% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error message.
Affected products
n/a · n/apublic PoCs found — 4
cve_referencewww.packetstormsecurity.org/0910-exploits/eurekamc-dos.txtunverifiedexploitdbwww.exploit-db.com/exploits/9881unverifiedexploitdbwww.exploit-db.com/exploits/10235unverifiedexploitdbwww.exploit-db.com/exploits/16443unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://osvdb.org/59262http://secunia.com/advisories/37132https://exchange.xforce.ibmcloud.com/vulnerabilities/53940http://www.packetstormsecurity.org/0910-exploits/eurekamc-dos.txthttp://www.securityfocus.com/archive/1/507376/100/0/threadedhttp://www.securityfocus.com/archive/1/508126/100/0/threadedhttp://www.vupen.com/english/advisories/2009/3025