CVE-2005-1255 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 42.8% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 42.81% — more likely to be exploited than 99% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-05-25 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| ipswitch | imail |
| ipswitch | imail server |
| ipswitch | ipswitch collaboration suite |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IPSwitch IMail Server 8.20 - IMAPD Remote Buffer Overflow | 2007-04-01 |
| exploit-db | IPSwitch IMail Server 8.15 - IMAPD Remote Code Execution | 2005-08-01 |
| exploit-db | IPSwitch IMAP Server - LOGON Remote Stack Overflow | 2005-06-07 |
References
- http://securitytracker.com/id?1014047
- http://www.idefense.com/application/poi/display?id=243&type=vulnerabilities
- http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html
- http://www.securityfocus.com/bid/13727
- http://securitytracker.com/id?1014047
- http://www.idefense.com/application/poi/display?id=243&type=vulnerabilities
- http://www.ipswitch.com/support/imail/releases/imail_professional/im82hf2.html
- http://www.securityfocus.com/bid/13727
→ the Explorer · watch your stack · NVD