Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary code via the (1) WebConnect and (2) Connect members in the (a) IMailServer control; (3) Sync3 and (4) Init3 members in the (b) IMailLDAPService control; and the (5) SetReplyTo member in the (c) IMailUserCollection control.
📦
imail_plus
Vendor: ipswitch
Actively Exploited
0
CISA KEV List
PoC / Exploits
1
Code Available
Total RCEs
2
Remote Access
Total CVEs
2
Total Indexed
Avg. EPSS
38.01%
Exploit Prob.
Security Vulnerability Index
Page 1 / 1
9.3
CVSS
CVE-2007-1637
RCE
Severity: HIGH
7.5
CVSS
CVE-2006-4379
RCE
Exploit Found
Stack-based buffer overflow in the SMTP Daemon in Ipswitch Collaboration 2006 Suite Premium and Standard Editions, IMail, IMail Plus, and IMail Secure allows remote attackers to execute arbitrary code via a long string located after an '@' character and before a ':' character.
Severity: HIGH