CVE-2007-0887

Axigen Mail Server 1.2.6-2.0.0b1 - Denial of Service via Malformed IMAP Login Credentials

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-0887. PoCs published by mu-b.

AI-analyzed exploit summary This exploit targets a NULL pointer dereference vulnerability in Axigen Mail Server versions 1.2.6 to 2.0.0b1, causing a denial-of-service (DoS) by sending malformed authentication data. The PoC connects to the IMAP service and triggers the crash by exploiting improper handling of the AUTHENTICATE PLAIN command.

Description

axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).

Exploits (1)

exploitdb WORKING POC VERIFIED
by mu-b · cdoslinux
https://www.exploit-db.com/exploits/3290

This exploit targets a NULL pointer dereference vulnerability in Axigen Mail Server versions 1.2.6 to 2.0.0b1, causing a denial-of-service (DoS) by sending malformed authentication data. The PoC connects to the IMAP service and triggers the crash by exploiting improper handling of the AUTHENTICATE PLAIN command.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Axigen Mail Server 1.2.6 - 2.0.0b1
No auth needed
Prerequisites: Network access to the target's IMAP service (port 143)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/33165
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3290
Third Party Advisory mailing-list x_refsource_fulldisc
http://marc.info/?l=full-disclosure&m=117094708423302&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/32345
Permissions Required third-party-advisory x_refsource_secunia
http://secunia.com/advisories/24073
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22473

Scores

EPSS 0.1011
EPSS Percentile 95.0%

Details

CWE
CWE-476
Status published
Products (2)
gecad_technologies/axigen_mail_server 1.2.6
gecad_technologies/axigen_mail_server 2.0.0b1
Published Feb 12, 2007
Tracked Since Feb 18, 2026