CVE-2005-4456 describes multiple buffer overflow vulnerabilities in MailEnable Professional 1.71 and Enterprise 1.1, specifically before patch ME-10009. These flaws allow unauthenticated remote attackers to trigger a denial of service or potentially execute arbitrary code by sending excessively long LIST, LSUB, or UID FETCH commands. With a CVSS score of 7.8, this vulnerability is considered highly severe due to its network-based attack vector and low attack complexity, leading to a complete loss of availability. While no active exploitation is noted, an ExploitDB entry exists for a related EXAMINE command overflow, and there is minimal community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.1CPE matchmatch criteria | cpe:2.3:a:mailenable:mailenable_enterprise:1.1:*:*:*:*:*:*:* | ||
1.71CPE matchmatch criteria | cpe:2.3:a:mailenable:mailenable_professional:1.71:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.