Back

CVE-2002-0925

Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary code via (1) the USER command to mmpop3d for mmmail 0.0.13 and earlier, (2) the HELO command to mmsmtpd for mmmail 0.0.13 and earlier, or (3) the USER command to mmftpd 0.0.7 and earlier.

Published: Oct 4, 2002 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
matthew_mondor mmftpd *
matthew_mondor mmmail *

GitHub Security Advisory GHSA-42x8-vcr5-wvrc

Format string vulnerability in mmsyslog function allows remote attackers to execute arbitrary...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.39%

Top 12% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub