Loading
Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication feature in IMailsec.dll, which triggers heap corruption in the IMail Server, or (2) a long SUBSCRIBE IMAP command, which triggers a stack-based buffer overflow in the IMAP Daemon.
Use CWE-119, Ipswitch vendor hub and Imail product page to widen CVE-2007-2795 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2005-1256, CVE-2005-1255 and CVE-2007-1637 for nearby disclosures in the same product family.