Ultrafunk's vulnerability footprint centers on its Popcorn product, a narrowly scoped offering that nonetheless appears in security tracking across multiple instances. The recurring signal involves memory-safety and bounds-checking issues that characterize firmware and systems-level components; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ultrafunk over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-1647HIGH Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of service (application crash) via a long string in a +OK response. | May 15, 2009 | 9.3 | 35 | NO | YES |
CVE-2002-1043MEDIUM Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t"). | Oct 4, 2002 | 5.0 | 23 | NO | YES |
CVE-2002-1044HIGH Buffer overflow in Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long Subject field. | Oct 4, 2002 | 7.5 | 20 | NO | NO |
CVE-2002-1045MEDIUM Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Date field that is converted into a year greater than 2037. | Oct 4, 2002 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ultrafunk.
Media articles that mention a CVE ID that affects a product developed by Ultrafunk — matched by CVE ID, not by vendor name.