7.8
CVE-2007-0887
- EPSS 10.11%
- Veröffentlicht 12.02.2007 23:28:00
- Zuletzt bearbeitet 16.06.2026 22:36:29
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gecad Technologies ≫ Axigen Mail Server Version1.2.6
Gecad Technologies ≫ Axigen Mail Server Version2.0.0b1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 10.11% | 0.95 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 10 | 6.9 |
AV:N/AC:L/Au:N/C:N/I:N/A:C
|
CWE-476 NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
http://marc.info/?l=full-disclosure&m=117094708423302&w=2
http://secunia.com/advisories/24073
http://www.securityfocus.com/bid/22473
http://osvdb.org/33165
https://exchange.xforce.ibmcloud.com/vulnerabilities/32345
https://www.exploit-db.com/exploits/3290