CVE-2007-2795

Ipswitch IMail <2006.21 - Buffer Overflow

Title source: llm

Description

Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.

Exploits (1)

exploitdb WORKING POC VERIFIED
by dmc · cremotewindows
https://www.exploit-db.com/exploits/9662

Scores

EPSS 0.1721
EPSS Percentile 95.0%

Details

CWE
CWE-119
Status published
Products (2)
ipswitch/imail 2006.1
ipswitch/imail < 2006.2
Published Jan 27, 2009
Tracked Since Feb 18, 2026