CVE-2006-3277

MailEnable Standard <1.92-Enterprise <2.0 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2006-3277. PoCs published by db0.

AI-analyzed exploit summary This Perl script exploits a denial-of-service vulnerability in MailEnable SMTP by sending a malformed HELO command with a null byte and extended character. The exploit repeatedly connects to the target SMTP service on port 25 and sends the crafted payload to crash the application.

Description

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by db0 · perldoswindows
https://www.exploit-db.com/exploits/28103

This Perl script exploits a denial-of-service vulnerability in MailEnable SMTP by sending a malformed HELO command with a null byte and extended character. The exploit repeatedly connects to the target SMTP service on port 25 and sends the crafted payload to crash the application.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: MailEnable SMTP (versions affected by CVE-2006-3277)
No auth needed
Prerequisites: Network access to the target SMTP service (port 25)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27387
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016376
Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2520
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20790
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/26791
Various Sources x_refsource_misc
http://www.divisionbyzero.be/?p=174
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18630
Patch x_refsource_misc
http://www.divisionbyzero.be/?p=173
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/438374/100/0/threaded

Scores

EPSS 0.0600
EPSS Percentile 92.4%

Details

CWE
CWE-399
Status published
Products (50)
mailenable/mailenable_enterprise < 1.00
mailenable/mailenable_professional 1.0.004
mailenable/mailenable_professional 1.0.005
mailenable/mailenable_professional 1.0.006
mailenable/mailenable_professional 1.0.007
mailenable/mailenable_professional 1.0.008
mailenable/mailenable_professional 1.0.009
mailenable/mailenable_professional 1.0.010
mailenable/mailenable_professional 1.0.011
mailenable/mailenable_professional 1.0.012
... and 40 more
Published Jun 28, 2006
Tracked Since Feb 18, 2026