CVE-2011-1430
- EPSS 0.42%
- Veröffentlicht 16.03.2011 22:55:04
- Zuletzt bearbeitet 11.04.2025 00:51:21
The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending a cleartext command that is pr...
- EPSS 35.81%
- Veröffentlicht 27.01.2009 23:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long S...
CVE-2007-5094
- EPSS 0.79%
- Veröffentlicht 26.09.2007 22:17:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a set of four different e-mail messages with a long boundary parameter in a certain malformed...
CVE-2007-1637
- EPSS 0.34%
- Veröffentlicht 23.03.2007 22:19:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Syn...
CVE-2005-2160
- EPSS 1.01%
- Veröffentlicht 06.07.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.
- EPSS 0.33%
- Veröffentlicht 25.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string a...
- EPSS 5.7%
- Veröffentlicht 25.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to cause a denial of service (crash) via a SELECT command with a large argument.
- EPSS 6.3%
- Veröffentlicht 25.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) ...
- EPSS 81.51%
- Veröffentlicht 25.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command wi...
- EPSS 11.63%
- Veröffentlicht 02.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via (1) a long user name or (2) a long password.