← Vulnerability feed

Vulnerability record · CVE-2004-0297 · published 23 November 2004

CVE-2004-0297: Ipswitch IMail LDAP daemon buffer overflow via large tag length

Ipswitch · Imail

The LDAP daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 has a buffer overflow triggered by an LDAP message with a large tag length. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw on an internet-facing mail component.

10.0 CVSS 2.0 High EPSS 68% · top 0.7%
10.0CVSS 2.0 base score
68%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via an LDAP message with a large tag length.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score of 10 with network reachability, no authentication and complete impact, combined with a very high EPSS score and an exploit-tagged reference.

What it is

The LDAP daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 has a buffer overflow triggered by an LDAP message with a large tag length. A remote, unauthenticated attacker can crash the service and potentially execute arbitrary code, making this a full-impact flaw on an internet-facing mail component.

Impact

An attacker gains the ability to crash the LDAP daemon and, per the description, execute arbitrary code in its context, which could yield complete compromise of confidentiality, integrity and availability.

Attack surface

Reached over the network via the LDAP service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required, only the ability to send a crafted LDAP message to the daemon.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is very high (0.68129, 99.3rd percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Apply the vendor hotfix referenced in the Ipswitch IMail 8.05 HF2 release notes, or upgrade to a fixed IMail version.
  • If patching is not immediately possible, restrict network access to the LDAP daemon (TCP 389 and any other configured LDAP ports) to trusted hosts only.
  • Disable or stop the iLDAP service if LDAP functionality is not required.
  • Monitor vendor and CERT/CC advisories for updated guidance and confirm the fixed build is deployed.

Detection

  • Monitor iLDAP.exe for crash or restart events and correlate with inbound LDAP traffic spikes.
  • Inspect LDAP traffic for messages with abnormally large tag lengths or malformed BER encoding.
  • Alert on unexpected processes spawned by or network connections originating from the iLDAP service host.
  • Review firewall and IDS logs for LDAP requests from untrusted external sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0297 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2005-1255Ipswitch imail vulnerabilityMultiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMai…EPSS 43%10.0CVE-2005-1256IMail IMAP daemon stack buffer overflow via STATUS commandThe IMAP daemon (IMAPD32.EXE) in Ipswitch IMail 8.13 and other versions before IMail Server 8.2 Hotfix 2 contains a stack-based buffer overflow trigg…EPSS 59%analysed10.0CVE-2002-0777Ipswitch imail vulnerabilityBuffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parame…EPSS 10%10.0CVE-1999-1046Ipswitch imail vulnerabilityBuffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long st…EPSS 15%9.3CVE-2007-1637Ipswitch imail vulnerabilityMultiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute …EPSS 5.6%9.0CVE-2007-2795Ipswitch imail memory buffer overflow vulnerabilityMultiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authen…EPSS 24%7.5CVE-2007-5094Ipswitch imail memory buffer overflow vulnerabilityHeap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary c…EPSS 4.4%7.5CVE-2005-2160Ipswitch imail cleartext storage of sensitive data vulnerabilityIMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information.EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2004-0297), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.