← Vulnerability feed

Vulnerability record · CVE-2005-2287 · published 18 July 2005

CVE-2005-2287: SoftiaCom wMailServer crash via malformed TCP packet

SSoftiacom · Wmailserver

SoftiaCom wMailServer 1.0 and 2.0 can be crashed by a remote attacker sending a large TCP packet with a leading space, possibly triggering a buffer overflow. The flaw is a denial of service in an internet-facing mail server, so availability of the mail service is the main concern.

5.0 CVSS 2.0 Medium EPSS 57% · top 1.0%
5.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityRemote unauthenticated denial of service with a possible buffer overflow, but impact is limited to availability and no confirmed code execution or active exploitation.

What it is

SoftiaCom wMailServer 1.0 and 2.0 can be crashed by a remote attacker sending a large TCP packet with a leading space, possibly triggering a buffer overflow. The flaw is a denial of service in an internet-facing mail server, so availability of the mail service is the main concern.

Impact

An unauthenticated remote attacker can crash the wMailServer application, disrupting mail service. The description only notes a possible buffer overflow, so code execution is not confirmed.

Attack surface

Reachable over the network via TCP; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV and no exploit tags appear in the references, though EPSS gives a 30-day probability of 0.568 (99th percentile), suggesting elevated interest.

What to do

  • Apply any vendor patch or upgrade for wMailServer; if none exists, treat the product as unsupported and plan replacement.
  • Restrict network access to the mail service with firewall rules or ACLs so only trusted hosts can reach it.
  • Place the service behind a filtering proxy or IDS/IPS that can drop oversized or malformed TCP packets.
  • Monitor the service for crashes and restart it automatically while a permanent fix is arranged.

Detection

  • Alert on wMailServer process crashes or unexpected restarts in application and system logs.
  • Inspect network traffic for large TCP packets containing a leading space directed at the mail service port.
  • Use IDS/IPS signatures for oversized or malformed TCP payloads targeting wMailServer.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-2287 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-2287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.