CVE-2025-42599
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- April 16, 2025
- Published Date
- April 18, 2025
- Last Updated
- April 18, 2025
- Vendor
- QUALITIA CO., LTD.
- Product
- Active! mail 6
- Description
- Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
- Tags
- Score
- 14.87% (Percentile: 94.16%) as of 2025-05-26
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v3.0
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
SSVC Information
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2025-04-28 00:00:00 UTC |
Recent Mentions
CISA Adds Three Known Exploited Vulnerabilities to Catalog
Source: All CISA Advisories • Published: 2025-04-28 12:00:00 UTC
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
cyruscostini/CVE-2025-42599
Type: github • Created: 2025-04-30 22:24:35 UTC • Stars: 0
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Proof of Concept Exploit Available