Record summary

CVE-2019-25646 has a selected CVSS score of 9.3 (critical); EIP currently links 1 catalogued exploit.

Description

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 24, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List2.5.1affected

Proofs of concept

1

Catalogued exploits

ExploitDBMail Carrier 2.5.1 - 'MAIL FROM' Buffer OverflowExploitDB exploitby Joseph McDonaghNot analyzed1 file
ExploitDB

PoC details

References

3