Back

CVE-2003-0391

Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in the PASS command.

Published: Jul 2, 2003 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
amax_information_technologies magic_winmail_server *

GitHub Security Advisory GHSA-953v-cmq7-xgqr

Format string vulnerability in Magic WinMail Server 2.3, and possibly other 2.x versions, allows...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.52%

Top 12% most likely to be exploited

Threat Score 31.1 / 100

Data Sources

NVD EPSS GitHub