CVE-2000-0971

Avirt Mail 4.0 and 4.2 - Denial of Service and Remote Code Execution via Long RCPT TO or MAIL FROM Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0971. PoCs published by Martin.

AI-analyzed exploit summary This exploit demonstrates a denial-of-service (DoS) vulnerability in Avirt Mail 4.0-4.2 by sending oversized 'MAIL FROM:' or 'RCPT TO:' fields, causing the application to crash. The PoC connects to the SMTP service and sends malformed commands with excessive character lengths.

Description

Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long "RCPT TO" or "MAIL FROM" command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Martin · cdoswindows
https://www.exploit-db.com/exploits/20311

This exploit demonstrates a denial-of-service (DoS) vulnerability in Avirt Mail 4.0-4.2 by sending oversized 'MAIL FROM:' or 'RCPT TO:' fields, causing the application to crash. The PoC connects to the SMTP service and sends malformed commands with excessive character lengths.

Classification
Working Poc 100%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Avirt Mail 4.0-4.2
No auth needed
Prerequisites: Network access to the SMTP service (port 25)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2000-10/0301.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5397
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/5398

Scores

EPSS 0.0558
EPSS Percentile 91.9%

Details

Status published
Products (2)
avirt/avirt_mail_server 4.0
avirt/avirt_mail_server 4.2
Published Dec 19, 2000
Tracked Since Feb 18, 2026