CVE-2007-2795
high · 9Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.
9
CVSS
24.5%
EPSS (exploit prob.)
98th
EPSS percentile
2009-01-27
Published
AV:N/AC:L/Au:S/C:C/I:C/A:C
Weaknesses
CWE-119
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| ipswitch | imail | <= 2006.2 |
| ipswitch | imail | 2006.1 |
Check a specific version with /api/v1/cve/match.
References
- http://www.ipswitch.com/support/imail/releases/im200621.asp
- http://www.zerodayinitiative.com/advisories/ZDI-07-042/
- http://www.zerodayinitiative.com/advisories/ZDI-07-043/
- http://www.ipswitch.com/support/imail/releases/im200621.asp
- http://www.zerodayinitiative.com/advisories/ZDI-07-042/
- http://www.zerodayinitiative.com/advisories/ZDI-07-043/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2007-2795