CVE-2005-4456
Multiple buffer overflows in MailEnable Professional 1.71 and Enterprise 1.1 before patch ME-10009 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via long (1) LIST, (2) LSUB, and (3) UID FETCH commands. NOTE: it is possible that these are alternate vectors for the issue described in CVE-2005-4402.
- Affected products
- Mailenable Enterprise, Mailenable Professional
- Mailenable Mailenable Enterprise
- = 1.1
- Mailenable Mailenable Professional
- = 1.71
- Fix
- Available
- CVSS 2.0
- 7.8 HIGH
- EPSS
- 7.1% (94th percentile)
- NVD status
- Modified
- Published
- 2005-12-21
CVE-2005-4456 at NVD
1 known exploit for CVE-2005-4456
Proof-of-concept code and exploit modules indexed by Sploitus