CVE-2004-2501
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute arbitrary code via (1) a long command string or (2) a long string to the MEIMAP service and then terminating the connection.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 14.06% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- mailenable/mailenable enterprise · mailenable/mailenable professional
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0349.htmlExploit, Patch, Vendor Advisory
- http://secunia.com/advisories/13318Patch, Vendor Advisory
- http://securitytracker.com/id?1012327Exploit, Patch, Vendor Advisory
- http://www.hat-squad.com/en/000102.htmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/12135
- http://www.osvdb.org/12136
- http://www.securityfocus.com/bid/11755Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18285
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18286
- http://archives.neohapsis.com/archives/bugtraq/2004-11/0349.htmlExploit, Patch, Vendor Advisory
- http://secunia.com/advisories/13318Patch, Vendor Advisory
- http://securitytracker.com/id?1012327Exploit, Patch, Vendor Advisory
- http://www.hat-squad.com/en/000102.htmlExploit, Patch, Vendor Advisory
- http://www.osvdb.org/12135
- http://www.osvdb.org/12136
- http://www.securityfocus.com/bid/11755Exploit, Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18285
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18286
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.