7.5
CVSSv2

CVE-2009-1516

Published: 04/05/2009 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent malicious users to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly demonstrated by a web application that accepts untrusted input for this method.

Vulnerable Product Search on Vulmon Subscribe to Product

icewarp merak mail server 9.4.1

Exploits

<?php /* Icewarp Merak Mail Server 941 IceWarpServerAPIObject/apidll Base64FileEncode() stack based buffer overflow poc by Nine:Situations:Group::surfista site: retrogodaltervistaorg/ apidll contains a stack based buffer overflow in the second argument of Base64FileEncode() method, this shared library can be loaded ...