CVE-2000-0985

All-Mail 1.1 - Remote Code Execution via Long MAIL FROM or RCPT TO Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0985. PoCs published by @stake.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in All-Mail SMTP server by sending a maliciously crafted 'mail from' command. It overwrites the return address with a JMP ESP instruction and executes arbitrary shellcode to run a command.

Description

Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO" command.

Exploits (1)

exploitdb WORKING POC VERIFIED
by @stake · cremotewindows
https://www.exploit-db.com/exploits/20287

This exploit targets a buffer overflow vulnerability in All-Mail SMTP server by sending a maliciously crafted 'mail from' command. It overwrites the return address with a JMP ESP instruction and executes arbitrary shellcode to run a command.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: All-Mail SMTP Server (Nevis Systems)
No auth needed
Prerequisites: Network access to the target SMTP server · Target running All-Mail SMTP Server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/1789
Exploit, Patch, Vendor Advisory vendor-advisory x_refsource_atstake
http://www.atstake.com/research/advisories/2000/a101200-2.txt

Scores

EPSS 0.0542
EPSS Percentile 91.7%

Details

Status published
Products (1)
nevis_systems/all-mail 1.1
Published Dec 19, 2000
Tracked Since Feb 18, 2026