5

CVE-2006-3277

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MailenableMailenable Enterprise Version <= 1.00
MailenableMailenable Enterprise Version <= 1.01
MailenableMailenable Enterprise Version <= 1.1
MailenableMailenable Enterprise Version <= 1.2
MailenableMailenable Enterprise Version <= 1.02
MailenableMailenable Enterprise Version <= 1.03
MailenableMailenable Enterprise Version <= 1.04
MailenableMailenable Enterprise Version <= 1.21
MailenableMailenable Professional Version1.0.004
MailenableMailenable Professional Version1.0.005
MailenableMailenable Professional Version1.0.006
MailenableMailenable Professional Version1.0.007
MailenableMailenable Professional Version1.0.008
MailenableMailenable Professional Version1.0.009
MailenableMailenable Professional Version1.0.010
MailenableMailenable Professional Version1.0.011
MailenableMailenable Professional Version1.0.012
MailenableMailenable Professional Version1.0.013
MailenableMailenable Professional Version1.0.014
MailenableMailenable Professional Version1.0.015
MailenableMailenable Professional Version1.0.016
MailenableMailenable Professional Version1.0.017
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 6% 0.924
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20790
Vendor Advisory
http://securitytracker.com/id?1016376
http://www.divisionbyzero.be/?p=173
Patch
http://www.divisionbyzero.be/?p=174
http://www.mailenable.com/hotfix/mesmtpc.zip
Patch
http://www.osvdb.org/26791
http://www.securityfocus.com/archive/1/438374/100/0/threaded
http://www.securityfocus.com/bid/18630
http://www.vupen.com/english/advisories/2006/2520
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27387