Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allow remote attackers to execute arbitrary code via a LOGIN command with (1) a long username argument or (2) a long username argument that begins with a special character.
📦
ipswitch_collaboration_suite
Vendor: ipswitch
Actively Exploited
0
CISA KEV List
PoC / Exploits
4
Code Available
Total RCEs
6
Remote Access
Total CVEs
13
Total Indexed
Avg. EPSS
27.99%
Exploit Prob.
Security Vulnerability Index
Page 2 / 2
10.0
CVSS
CVE-2005-1255
Exploit Found
Severity: HIGH
5.0
CVSS
The IMAP daemon (IMAPD32.EXE) in Ipswitch Collaboration Suite (ICS) allows remote attackers to cause a denial of service (CPU consumption) via an LSUB command with a large number of null characters, which causes an infinite loop.
Severity: MEDIUM
7.2
CVSS
Buffer overflow in the IMAP daemon (IMAP4d32.exe) for Ipswitch Collaboration Suite (ICS) before 8.15 Hotfix 1 allows remote authenticated users to execute arbitrary code via a long EXAMINE command.
Severity: HIGH