9
CVSSv2

CVE-2008-1277

Published: 10/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and previous versions allows remote malicious users to cause a denial of service (crash) via (1) SEARCH and (2) APPEND commands without required arguments, which triggers a NULL pointer dereference.

Vulnerable Product Search on Vulmon Subscribe to Product

mailenable mailenable enterprise

mailenable mailenable professional

Exploits

source: wwwsecurityfocuscom/bid/28145/info MailEnable is prone to multiple remote vulnerabilities in the IMAP service, including: - Multiple buffer-overflow vulnerabilities - Multiple denial-of-service vulnerabilities due to a NULL-pointer exception An attacker may leverage these issues to execute arbitrary code in the context of the ...