Vulnerability record · CVE-2005-2287 · published 18 July 2005
CVE-2005-2287: SoftiaCom wMailServer crash via malformed TCP packet
SSoftiacom · Wmailserver
SoftiaCom wMailServer 1.0 and 2.0 can be crashed by a remote attacker sending a large TCP packet with a leading space, possibly triggering a buffer overflow. The flaw is a denial of service in an internet-facing mail server, so availability of the mail service is the main concern.
Description
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large TCP packet with a leading space, possibly triggering a buffer overflow.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated denial of service with a possible buffer overflow, but impact is limited to availability and no confirmed code execution or active exploitation.
What it is
SoftiaCom wMailServer 1.0 and 2.0 can be crashed by a remote attacker sending a large TCP packet with a leading space, possibly triggering a buffer overflow. The flaw is a denial of service in an internet-facing mail server, so availability of the mail service is the main concern.
Impact
An unauthenticated remote attacker can crash the wMailServer application, disrupting mail service. The description only notes a possible buffer overflow, so code execution is not confirmed.
Attack surface
Reachable over the network via TCP; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, though EPSS gives a 30-day probability of 0.568 (99th percentile), suggesting elevated interest.
What to do
- Apply any vendor patch or upgrade for wMailServer; if none exists, treat the product as unsupported and plan replacement.
- Restrict network access to the mail service with firewall rules or ACLs so only trusted hosts can reach it.
- Place the service behind a filtering proxy or IDS/IPS that can drop oversized or malformed TCP packets.
- Monitor the service for crashes and restart it automatically while a permanent fix is arranged.
Detection
- Alert on wMailServer process crashes or unexpected restarts in application and system logs.
- Inspect network traffic for large TCP packets containing a leading space directed at the mail service port.
- Use IDS/IPS signatures for oversized or malformed TCP payloads targeting wMailServer.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-2287 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-2287), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.