Vulnerability Details CVE-2005-4456
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.045
EPSS Ranking 88.5%
CVSS Severity
CVSS v2 Score 7.8
Products affected by CVE-2005-4456
-
cpe:2.3:a:mailenable:mailenable_enterprise:1.1
-
cpe:2.3:a:mailenable:mailenable_professional:1.71