CVE-2007-3925
60Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 85%
from disclosure to weapon4 days
Published on NVDJul 21
1st PoC+4d
metasploitJul 18
exploitation probability
85%top 1% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
Multiple buffer overflows in the IMAP service (imapd32.exe) in Ipswitch IMail Server 2006 before 2006.21 allow remote authenticated users to execute arbitrary code via the (1) Search or (2) Search Charset command.
Affected products
n/a · n/apublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/16487unverifiedexploitdbwww.exploit-db.com/exploits/4223unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://docs.ipswitch.com/IMail%202006.21/ReleaseNotes/IMail_RelNotes.htm#NewReleasehttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=563http://secunia.com/advisories/26123https://exchange.xforce.ibmcloud.com/vulnerabilities/35496https://exchange.xforce.ibmcloud.com/vulnerabilities/35500http://www.securityfocus.com/bid/24962http://www.securitytracker.com/id?1018419http://www.vupen.com/english/advisories/2007/2574