CVE-2002-1539

MDaemon <= 6.0.7 - Authenticated Denial of Service via Long DELE or UIDL Arguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1539. PoCs published by D4rkGr3y.

AI-analyzed exploit summary This exploit demonstrates a buffer overflow vulnerability in MDaemon's POP server by sending malformed UIDL and DELE commands with large integer values, causing the service to crash. The PoC shows the interaction with the POP server and the resulting denial of service.

Description

Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments.

Exploits (1)

exploitdb WORKING POC VERIFIED
by D4rkGr3y · textdoswindows
https://www.exploit-db.com/exploits/21965

This exploit demonstrates a buffer overflow vulnerability in MDaemon's POP server by sending malformed UIDL and DELE commands with large integer values, causing the service to crash. The PoC shows the interaction with the POP server and the resulting denial of service.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: MDaemon 6.0.5
Auth required
Prerequisites: Access to the POP server · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/10488.php
Exploit, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2002-10/0382.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6053

Scores

EPSS 0.0321
EPSS Percentile 86.5%

Details

Status published
Products (4)
alt-n/mdaemon 6.0
alt-n/mdaemon 6.0.5
alt-n/mdaemon 6.0.6
alt-n/mdaemon 6.0.7
Published Mar 31, 2003
Tracked Since Feb 18, 2026