CVE-2006-6290
Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.30 and 2.0 through 2.33 allow remote authenticated users to cause a denial…
Does this matter?
Lower severity and a low EPSS score (3.25%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.30 and 2.0 through 2.33 allow remote authenticated users to cause a denial of service (crash) or possibly execute arbitrary code via a long argument to the (1) EXAMINE or (2) SELECT command.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 3.25% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- mailenable/mailenable enterprise · mailenable/mailenable professional
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/23047
- http://secunia.com/advisories/23080
- http://secunia.com/secunia_research/2006-71/advisory/Patch, Vendor Advisory
- http://securitytracker.com/id?1017276
- http://securitytracker.com/id?1017319
- http://www.mailenable.com/hotfix/Patch
- http://www.securityfocus.com/archive/1/453118/100/100/threaded
- http://www.securityfocus.com/bid/21362
- http://www.vupen.com/english/advisories/2006/4673
- http://www.vupen.com/english/advisories/2006/4778
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30614
- http://secunia.com/advisories/23047
- http://secunia.com/advisories/23080
- http://secunia.com/secunia_research/2006-71/advisory/Patch, Vendor Advisory
- http://securitytracker.com/id?1017276
- http://securitytracker.com/id?1017319
- http://www.mailenable.com/hotfix/Patch
- http://www.securityfocus.com/archive/1/453118/100/100/threaded
- http://www.securityfocus.com/bid/21362
- http://www.vupen.com/english/advisories/2006/4673
- http://www.vupen.com/english/advisories/2006/4778
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30614
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.