CVE-2007-2795 EXPLOIT
9.0
HIGH · CVSS 2.0 · EPSS 24.5% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.
Scoring
| CVSS | 9.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
| EPSS | 24.46% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2009-01-27 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ipswitch | imail |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | IPSwitch IMAP Server 9.20 - Remote Buffer Overflow | 2009-09-14 |
References
- http://www.ipswitch.com/support/imail/releases/im200621.asp
- http://www.zerodayinitiative.com/advisories/ZDI-07-042/
- http://www.zerodayinitiative.com/advisories/ZDI-07-043/
- http://www.ipswitch.com/support/imail/releases/im200621.asp
- http://www.zerodayinitiative.com/advisories/ZDI-07-042/
- http://www.zerodayinitiative.com/advisories/ZDI-07-043/
→ the Explorer · watch your stack · NVD