peter bassill · operator
$ cve CVE-2006-3277 JSON

CVE-2006-3277 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 6.1% (pctl 93)

Patch early

A public exploit exists.

Description

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS6.11% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2006-06-28
Last modified2026-06-16

Affected (2)

VendorProduct
mailenablemailenable enterprise
mailenablemailenable professional

Public exploits

SourceTitleDate
exploit-dbMailEnable 1.x - SMTP 'HELO' Remote Denial of Service2006-06-24

References

→ the Explorer  ·  watch your stack  ·  NVD