Eudora

Vendor:

First CVE: Jul 29, 1998 · Active for 27 years

24
Total CVEs
More Total CVEs than 95% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Eudora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 29, 1998
27 years ago
Most Recent CVE
Jun 11, 2007
6,984 days ago

CVE Severity & Scoring

Eudora24 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (4.2%)
Unknown23 (95.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (4.2%)
High0 (0.0%)
Unknown23 (95.8%)
User Interaction
None1 (4.2%)
Unknown23 (95.8%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (4.2%)
Unknown23 (95.8%)

Top CVEs

Signals from CVEs in this product scope (24 CVEs).

24 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long SMTP reply. NOTE: the user must click through a warning ab
May 21, 20079.333NOYES
Buffer overflow in Eudora for Windows 5.2.1, 6.0.3, and 6.1 allows remote attackers to execute arbitrary code via an e-mail with (1) a link to a long URL to the C drive or (2) a lo
May 6, 20045.132NOYES
Eudora 5.1 allows remote attackers to bypass security warnings and possibly execute arbitrary code via attachments with names containing a trailing "." (dot).
Dec 31, 20026.432NOYES
Eudora 4.x allows remote attackers to bypass the user warning for executable attachments such as .exe, .com, and .bat by using a .lnk file that refers to the attachment, aka "Steal
Apr 28, 20007.532NOYES
Buffer overflow in Eudora 5.1.1 and 5.0-J for Windows, and possibly other versions, allows remote attackers to execute arbitrary code via a multi-part message with a long boundary
Aug 12, 20027.529NOYES
Eudora before 5.1 allows a remote attacker to execute arbitrary code, when the 'Use Microsoft Viewer' and 'allow executables in HTML content' options are enabled, via an HTML email
Jun 27, 20017.529NOYES
Eudora 5.1 allows remote attackers to execute arbitrary code when the "Use Microsoft Viewer" option is enabled and the "allow executables in HTML content" option is disabled, via a
May 29, 20017.529NOYES
Buffer overflow in Qualcomm Eudora 7.1.0.9 allows user-assisted, remote IMAP servers to execute arbitrary code via a long FLAGS response to a SELECT INBOX command.
Jun 11, 20076.827NOYES
Microsoft HTML control as used in (1) Internet Explorer 5.0, (2) FrontPage Express, (3) Outlook Express 5, and (4) Eudora, and possibly others, allows remote malicious web site or
Aug 27, 19995.025NOYES
Eudora 6.1 and 6.0.3 for Windows allows remote attackers to cause a denial of service (crash) via a deeply nested multipart MIME message.
Apr 14, 20045.023NOYES

Exploit Exposure

Signals from CVEs in this product scope (24 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
13 CVEs
54.2% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (24 CVEs).

Media Mentions

Signals from CVEs in this product scope (24 CVEs).

Top CNAs Publishing CVEs For Eudora

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.1.0.916.82.1%01
7.119.32.9%01
6.2.0.1415.01.7%01
6.1.116.42.6%01
6.125.02.7%02
6.0.325.02.7%02
6.0.125.83.1%02
6.025.83.1%02
5.2.165.32.5%04
5.225.71.7%01
5.1.137.11.5%01
5.146.02.0%02
5.0j17.53.0%01
5.0.226.32.1%01
4.326.31.0%00
4.226.31.0%00
4.017.53.5%01