peter bassill · operator
$ cve CVE-2007-2795 JSON

CVE-2007-2795 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 24.5% (pctl 98)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS24.46% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-01-27
Last modified2026-06-16

Affected (1)

VendorProduct
ipswitchimail

Public exploits

SourceTitleDate
exploit-dbIPSwitch IMAP Server 9.20 - Remote Buffer Overflow2009-09-14

References

→ the Explorer  ·  watch your stack  ·  NVD