PoC Index

CVE-2007-0955

HIGH 7.8EPSS 5.3%

The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.

CVSS v2.0
7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS
5.33% chance of exploitation in the next 30 days, 92th percentile
Published
2007-02-15
Updated
2024-08-07

Proof-of-concept exploits (3)

ExploitDB entries (2)

References

Related