← Vulnerability feed

Vulnerability record · CVE-2005-1256 · published 25 May 2005

CVE-2005-1256: IMail IMAP daemon stack buffer overflow via STATUS command

Ipswitch · Imail

The IMAP daemon (IMAPD32.EXE) in Ipswitch IMail 8.13 and other versions before IMail Server 8.2 Hotfix 2 contains a stack-based buffer overflow triggered by a STATUS command with an overly long mailbox name. A remote authenticated user can corrupt the stack and potentially execute arbitrary code on the mail server.

10.0 CVSS 2.0 High EPSS 59% · top 0.9%
10.0CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is a remotely reachable stack buffer overflow with a CVSS 2.0 score of 10 and a very high EPSS percentile, though exploitation requires valid IMAP credentials and no public exploit is confirmed.

What it is

The IMAP daemon (IMAPD32.EXE) in Ipswitch IMail 8.13 and other versions before IMail Server 8.2 Hotfix 2 contains a stack-based buffer overflow triggered by a STATUS command with an overly long mailbox name. A remote authenticated user can corrupt the stack and potentially execute arbitrary code on the mail server.

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the IMAP daemon, giving full control of the mail server process and potentially the host. This can lead to data compromise, mail interception, or use of the server as a pivot point.

Attack surface

Reachable over the network through the IMAP service; the CVSS vector indicates no authentication is required, though the description states the attacker must be a remote authenticated user, so valid IMAP credentials are needed. No user interaction is required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS shows a high 30-day probability (0.589, 99th percentile), and references include a vendor advisory and patch, but no public exploit code is confirmed in the record.

What to do

  • Apply IMail Server 8.2 Hotfix 2 or later, which the vendor patch reference addresses.
  • If patching is not immediately possible, restrict IMAP access to trusted networks or disable the IMAP service until the fix is applied.
  • Enforce strong, unique credentials and monitor for unusual authenticated IMAP sessions to limit abuse of the authenticated attack path.
  • Segment the mail server from other critical systems to reduce the blast radius if code execution occurs.

Detection

  • Monitor IMAP logs for STATUS commands containing abnormally long mailbox names or malformed arguments.
  • Alert on IMAPD32.EXE crashes or unexpected process terminations on IMail servers.
  • Watch for post-exploitation behavior such as new processes spawned by the IMAP daemon or outbound connections from the mail server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-1256 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-3927Ipswitch imail server vulnerabilityMultiple buffer overflows in Ipswitch IMail Server 2006 before 2006.21 (1) allow remote attackers to execute arbitrary code via unspecified vectors i…EPSS 22%10.0CVE-2005-1255Ipswitch imail vulnerabilityMultiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMai…EPSS 43%10.0CVE-2004-0297Ipswitch IMail LDAP daemon buffer overflow via large tag lengthThe LDAP daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 has a buffer overflow triggered by an LDAP message with a large tag length. A rem…EPSS 68%analysed10.0CVE-2002-0777Ipswitch imail vulnerabilityBuffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parame…EPSS 10%10.0CVE-1999-1046Ipswitch imail vulnerabilityBuffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long st…EPSS 15%9.8CVE-2017-12638Ipswitch imail server memory buffer overflow vulnerabilityStack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vec…EPSS 2.5%9.8CVE-2017-12639Ipswitch imail server memory buffer overflow vulnerabilityStack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vec…EPSS 2.5%9.3CVE-2007-1637Ipswitch imail vulnerabilityMultiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute …EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2005-1256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.