Loading...
Loading...
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
December 31, 2004
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2004-2677
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.