← Vulnerability feed

Vulnerability record · CVE-2005-3155 · published 5 October 2005

CVE-2005-3155: MailEnable W3C logging buffer overflow allows remote code execution

Mailenable · Mailenable Enterprise

MailEnable Enterprise 1.1 and Professional 1.6 contain a buffer overflow in the W3C logging component. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The flaw matters because mail servers are internet-facing and this path requires no credentials.

7.5 CVSS 2.0 High EPSS 64% · top 0.8%
7.5CVSS 2.0 base score
64%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution in an internet-facing mail server with a high EPSS score, though no confirmed in-the-wild exploitation is documented.

What it is

MailEnable Enterprise 1.1 and Professional 1.6 contain a buffer overflow in the W3C logging component. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The flaw matters because mail servers are internet-facing and this path requires no credentials.

Impact

An attacker can corrupt memory in the logging process and, if the overflow is reliably controlled, execute arbitrary code with the privileges of the MailEnable service. At minimum, a crash of the logging component is achievable.

Attack surface

The vulnerability is network-reachable (CVSS vector AV:N/AC:L/Au:N) and requires no authentication or user interaction. It is triggered through the W3C logging functionality, meaning crafted requests handled by the affected MailEnable service reach the vulnerable code path.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.63694, 99.18th percentile), and references include vendor patch and advisory links, but no public exploit tag is present in the record.

What to do

  • Apply the vendor hotfix from mailenable.com/hotfix and the patch referenced in Secunia advisory 17010.
  • If patching cannot be done immediately, restrict network access to the MailEnable SMTP/HTTP services to trusted sources only.
  • Disable or reduce W3C logging if it is not operationally required, to remove the vulnerable code path.
  • Run the MailEnable service under a least-privileged account to limit the impact of code execution.
  • Monitor vendor advisories for updated builds covering Enterprise 1.1 and Professional 1.6.

Detection

  • Review MailEnable service crash logs and Windows event logs for repeated faults in the logging component.
  • Inspect W3C log files and inbound requests for unusually long or malformed fields that could trigger the overflow.
  • Alert on unexpected child processes or command execution spawned by the MailEnable service account.
  • Correlate network traffic to MailEnable ports with crash or restart events on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-3155 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6997Mailenable enterprise improper authentication vulnerabilityUnspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi…EPSS 1.8%10.0CVE-2006-6605Mailenable enterprise vulnerabilityStack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41,…EPSS 5.9%10.0CVE-2006-6423MailEnable IMAP Service Pre-Auth Stack Buffer OverflowMailEnable Professional and Enterprise IMAP service contains a stack-based buffer overflow reachable before authentication. A remote attacker can sen…EPSS 71%analysed10.0CVE-2006-1792Mailenable enterprise vulnerabilityUnspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition bef…EPSS 1.8%10.0CVE-2005-2222Mailenable professional vulnerabilityUnknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.EPSS 1.4%9.3CVE-2006-5176Mailenable enterprise memory buffer overflow vulnerabilityBuffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the s…EPSS 5.4%9.3CVE-2006-5177Mailenable enterprise memory buffer overflow vulnerabilityThe NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vecto…EPSS 7.1%9.0CVE-2008-1276Mailenable enterprise memory buffer overflow vulnerabilityMultiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote a…EPSS 7.1%

Source: NIST National Vulnerability Database (record CVE-2005-3155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.