Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Apr 16, 2026
CVE-2004-2677
CVE-2004-2677
Description
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
Affected products
1- cpe:2.3:a:qwikmail:qwikmail_smtp:0.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- qwikmail.sourceforge.net/smtpd/qwik-smtpd-0.3.patchnvdPatch
- secunia.com/advisories/13037nvdPatchVendor Advisory
- securitytracker.com/idnvdPatchVendor Advisory
- www.securityfocus.com/bid/11572nvdExploitPatchVendor Advisory
- unl0ck.info/advisories/qwik-smtpd.txtnvd
- www.securityfocus.com/archive/1/460600/100/0/threadednvd
- www.vupen.com/english/advisories/2007/0687nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/17917nvd
News mentions
0No linked articles in our index yet.