10
CVSSv2

CVE-2007-0886

Published: 12/02/2007 Updated: 19/10/2017
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 1000
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Heap-based buffer underflow in axigen 1.2.6 up to and including 2.0.0b1 allows remote malicious users to cause a denial of service (application crash) and possibly execute arbitrary code via certain base64-encoded data on the pop3 port (110/tcp), which triggers an integer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

gecad technologies axigen mail server 1.2.6

gecad technologies axigen mail server 2.0.0b1

Exploits

/* doaxigenc * * axigen 126 - 200b1 DoS (x86-lnx) * by mu-b - Sat Oct 22 2006 * * - Tested on: AXIGEN 126 (lnx) * AXIGEN 200b1 (lnx) * * 0x08088054: parsing error results in DoS (little-endian, confirmed) * DoS + off-by-one heap smash (big-endian) * * Note: if you receive a SIGPI ...