5
CVSSv2

CVE-2006-3277

Published: 28/06/2006 Updated: 18/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

The SMTP service of MailEnable Standard 1.92 and previous versions, Professional 2.0 and previous versions, and Enterprise 2.0 and previous versions before the MESMTPC hotfix, allows remote malicious users to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.

Vulnerable Product Search on Vulmon Subscribe to Product

mailenable mailenable professional 1.0.007

mailenable mailenable professional 1.0.008

mailenable mailenable professional 1.0.016

mailenable mailenable professional 1.0.017

mailenable mailenable professional 1.106

mailenable mailenable professional 1.107

mailenable mailenable professional 1.114

mailenable mailenable professional 1.115

mailenable mailenable professional 1.18

mailenable mailenable professional 1.19

mailenable mailenable professional 1.5018

mailenable mailenable professional 1.51

mailenable mailenable professional 1.701

mailenable mailenable professional 1.702

mailenable mailenable professional 1.91

mailenable mailenable professional 1.92

mailenable mailenable enterprise

mailenable mailenable professional 1.0.005

mailenable mailenable professional 1.0.006

mailenable mailenable professional 1.0.013

mailenable mailenable professional 1.0.014

mailenable mailenable professional 1.0.015

mailenable mailenable professional 1.104

mailenable mailenable professional 1.105

mailenable mailenable professional 1.112

mailenable mailenable professional 1.113

mailenable mailenable professional 1.16

mailenable mailenable professional 1.17

mailenable mailenable professional 1.5016

mailenable mailenable professional 1.5017

mailenable mailenable professional 1.610

mailenable mailenable professional 1.7

mailenable mailenable professional 1.8

mailenable mailenable professional 1.9

mailenable mailenable professional 1.0.009

mailenable mailenable professional 1.0.010

mailenable mailenable professional 1.1

mailenable mailenable professional 1.101

mailenable mailenable professional 1.108

mailenable mailenable professional 1.109

mailenable mailenable professional 1.116

mailenable mailenable professional 1.12

mailenable mailenable professional 1.2

mailenable mailenable professional 1.2a

mailenable mailenable professional 1.52

mailenable mailenable professional 1.53

mailenable mailenable professional 1.703

mailenable mailenable professional 1.704

mailenable mailenable professional 1.71

mailenable mailenable professional 1.93

mailenable mailenable professional 1.0.004

mailenable mailenable professional 1.0.011

mailenable mailenable professional 1.0.012

mailenable mailenable professional 1.102

mailenable mailenable professional 1.103

mailenable mailenable professional 1.110

mailenable mailenable professional 1.111

mailenable mailenable professional 1.13

mailenable mailenable professional 1.14

mailenable mailenable professional 1.15

mailenable mailenable professional 1.5

mailenable mailenable professional 1.5015

mailenable mailenable professional 1.54

mailenable mailenable professional 1.6

mailenable mailenable professional 1.72

mailenable mailenable professional 1.73

Exploits

source: wwwsecurityfocuscom/bid/18630/info MailEnable is prone to a remote denial-of-service vulnerability This issue allows remote attackers to crash the application, denying further service to legitimate users #!/usr/bin/perl -w # # Mailenable SMTP DoS exploit # 24/06/2006 # # Filbert at divisionbyzero dot be # use Net::Telnet; $s ...