Vulnerabilities > CVE-2007-0955 - Denial-Of-Service vulnerability in MailEnable Professional

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
mailenable
exploit available

Summary

The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.

Exploit-Db

descriptionMailEnable Professional/Enterprise <= 2.35 Out of Bounds DoS Exploit. CVE-2007-0955. Dos exploit for windows platform
idEDB-ID:3306
last seen2016-01-31
modified2007-02-14
published2007-02-14
reportermu-b
sourcehttps://www.exploit-db.com/download/3306/
titleMailEnable Professional/Enterprise <= 2.35 Out of Bounds DoS Exploit