CVE-2003-1452

Qualcomm qpopper <4.05 - Code Injection

Title source: llm
STIX 2.1

Description

Untrusted search path vulnerability in Qualcomm qpopper 4.0 through 4.05 allows local users to execute arbitrary code by modifying the PATH environment variable to reference a malicious smbpasswd program.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Xpl017Elz · clocallinux
https://www.exploit-db.com/exploits/21

Scores

EPSS 0.0035
EPSS Percentile 57.5%

Details

CWE
CWE-16
Status published
Products (8)
qualcomm/qpopper 4.0
qualcomm/qpopper 4.0.1
qualcomm/qpopper 4.0.2
qualcomm/qpopper 4.0.3
qualcomm/qpopper 4.0.4
qualcomm/qpopper 4.0.5
qualcomm/qpopper 4.0.5_fc2
qualcomm/qpopper 4.0_b14
Published Dec 31, 2003
Tracked Since Feb 18, 2026