CVE-2007-2795
Ipswitch IMail <2006.21 - Buffer Overflow
Title source: llmDescription
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.
Exploits (1)
Scores
EPSS
0.1721
EPSS Percentile
95.0%
Details
CWE
CWE-119
Status
published
Products (2)
ipswitch/imail
2006.1
ipswitch/imail
< 2006.2
Published
Jan 27, 2009
Tracked Since
Feb 18, 2026