CVE-2006-3277 EXPLOIT
5.0
MEDIUM · CVSS 2.0 · EPSS 6.1% (pctl 93)
Patch early
A public exploit exists.
Description
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
Scoring
| CVSS | 5.0 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:P |
| EPSS | 6.11% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-399 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-28 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mailenable | mailenable enterprise |
| mailenable | mailenable professional |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MailEnable 1.x - SMTP 'HELO' Remote Denial of Service | 2006-06-24 |
References
- http://secunia.com/advisories/20790
- http://securitytracker.com/id?1016376
- http://www.divisionbyzero.be/?p=173
- http://www.divisionbyzero.be/?p=174
- http://www.mailenable.com/hotfix/mesmtpc.zip
- http://www.osvdb.org/26791
- http://www.securityfocus.com/archive/1/438374/100/0/threaded
- http://www.securityfocus.com/bid/18630
- http://www.vupen.com/english/advisories/2006/2520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27387
- http://secunia.com/advisories/20790
- http://securitytracker.com/id?1016376
- http://www.divisionbyzero.be/?p=173
- http://www.divisionbyzero.be/?p=174
- http://www.mailenable.com/hotfix/mesmtpc.zip
- http://www.osvdb.org/26791
- http://www.securityfocus.com/archive/1/438374/100/0/threaded
- http://www.securityfocus.com/bid/18630
- http://www.vupen.com/english/advisories/2006/2520
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27387
→ the Explorer · watch your stack · NVD