9.3

CVE-2007-1637

Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the (5) SetReplyTo member in the (c) IMailUserCollection control.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ipswitch ≫ Imail Version 2006
Ipswitch ≫ Imail Plus Version 2006
Ipswitch ≫ Imail Premium Version 2006
Ipswitch ≫ Ipswitch Collaboration Suite Version 2006_standard
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.63% 0.919
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=487
http://secunia.com/advisories/24422
Vendor Advisory
http://support.ipswitch.com/kb/IM-20070305-JH01.htm
http://www.securitytracker.com/id?1017737
http://www.vupen.com/english/advisories/2007/0853