CVE-2006-3277

MailEnable Standard <1.92-Enterprise <2.0 - DoS

Title source: llm
STIX 2.1

Description

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.

Exploits (1)

exploitdb WORKING POC VERIFIED
by db0 · perldoswindows
https://www.exploit-db.com/exploits/28103

Scores

EPSS 0.2104
EPSS Percentile 95.7%

Details

CWE
CWE-399
Status published
Products (50)
mailenable/mailenable_enterprise < 1.00
mailenable/mailenable_professional 1.0.004
mailenable/mailenable_professional 1.0.005
mailenable/mailenable_professional 1.0.006
mailenable/mailenable_professional 1.0.007
mailenable/mailenable_professional 1.0.008
mailenable/mailenable_professional 1.0.009
mailenable/mailenable_professional 1.0.010
mailenable/mailenable_professional 1.0.011
mailenable/mailenable_professional 1.0.012
... and 40 more
Published Jun 28, 2006
Tracked Since Feb 18, 2026