CVE-2003-0264
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 71%
from disclosure to weapon560 days
Published on NVDMay 8
1st PoC+560d
metasploitMay 7
exploitation probability
71%top 1% of all CVEs
observed exploitation
nono source reports it
12 public exploit(s)
Multiple buffer overflows in SLMail 5.1.0.4420 allows remote attackers to execute arbitrary code via (1) a long EHLO argument to slmail.exe, (2) a long XTRN argument to slmail.exe, (3) a long string to POPPASSWD, or (4) a long password to the POP3 server.
Affected products
n/a · n/apublic PoCs found — 12✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/16399exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/638exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/643exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/646githubgithub.com/pwncone/CVE-2003-0264-SLmail-5.5★ 0githubgithub.com/vrikodar/CVE-2003-0264_EXPLOIT★ 0githubgithub.com/TheMalwareGuardian/CVE-2003-0264★ 0githubgithub.com/nobodyatall648/CVE-2003-0264★ 0githubgithub.com/adenkiewicz/CVE-2003-0264★ 0githubgithub.com/fyoderxx/slmail-exploit★ 0githubgithub.com/war4uthor/CVE-2003-0264★ 0cve_referencepacketstormsecurity.com/files/161526/SLMail-5.1.0.4420-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.