CRITICAL

CVE-2025-42599

Qualitia Active\! Mail 2025-04-18 CVSS v3.1
CVSS
9.8
KEV

Description

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

Summary dbcve.org

Stack-based buffer overflow vulnerability in Active! mail 6 (BuildInfo 6.60.05008561 and earlier) allows remote unauthenticated attackers to send specially crafted requests that can overwrite stack memory, potentially leading to arbitrary code execution or denial of service.

Mitigation

Update Active! mail 6 to the latest patched version. If patching is delayed, restrict network access to the mail service using firewalls or network segmentation to limit exposure to untrusted sources.

Weakness (CWE)

CWE-121 Stack-based Buffer Overflow

EPSS Score

3.3%
Probability of exploitation in next 30 days
88th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE