peter bassill · operator
$ cve CVE-2007-5466 JSON

CVE-2007-5466 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 19.9% (pctl 97)

Patch early

A public exploit exists.

Description

Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execute arbitrary code via a long string in an IMAP AUTHENTICATE PLAIN action, involving the ifParseAuthPlain function; (3) execute arbitrary code via a long LOGIN command to the admin interface port (4501/tcp); or (4) execute arbitrary code via a long string in an IMAP AUTHENTICATE LOGIN (aka CRAM-MD5 authentication) action, involving the ifProcImapAuth1 function.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS19.89% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-10-15
Last modified2026-06-16

Affected (1)

VendorProduct
extremailextremail

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD