{"api_version":"1","generated_at":"2026-07-24T19:34:03+00:00","cve":"CVE-2007-4607","urls":{"html":"https://cve.report/CVE-2007-4607","api":"https://cve.report/api/cve/CVE-2007-4607.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4607","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4607"},"summary":{"title":"CVE-2007-4607","description":"Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-08-31 00:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://community.ivanti.com/docs/DOC-50988","name":"https://community.ivanti.com/docs/DOC-50988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36307","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36307","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26639","name":"http://secunia.com/advisories/26639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PostCast Server EasyMail SMTP ActiveX Control Buffer Overflow - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html","name":"http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"https://www.exploit-db.com/exploits/4328","name":"https://www.exploit-db.com/exploits/4328","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Postcast Server Pro 3.0.61 / Quiksoft EasyMail  (emsmtp.dll 6.0.1) BoF","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25467","name":"http://www.securityfocus.com/bid/25467","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"EasyMail Objects EMSMTP.DLL ActiveX Control Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://osvdb.org/38335","name":"http://osvdb.org/38335","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/281977","name":"http://www.kb.cert.org/vuls/id/281977","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#281977 - Quiksoft EasyMail SMTP ActiveX control stack buffer overflow vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://retrogod.altervista.org/postcast-emsmtp_bof.html","name":"http://retrogod.altervista.org/postcast-emsmtp_bof.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Error 404 :(","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/24199","name":"http://secunia.com/advisories/24199","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"EasyMail Objects IMAP4 and SMTP Components Buffer Overflows - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4607","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4607","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4607","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"gate_comm_software","cpe5":"postcast_server_pro","cpe6":"3.0.61","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"4607","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"quicksoft","cpe5":"easymail_objects","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.731Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"25467","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25467"},{"name":"VU#281977","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/281977"},{"name":"24199","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24199"},{"name":"26639","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26639"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://retrogod.altervista.org/postcast-emsmtp_bof.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"https://community.ivanti.com/docs/DOC-50988"},{"name":"38335","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/38335"},{"name":"easymail-submittoexpress-bo(36307)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36307"},{"name":"4328","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4328"},{"name":"20130424 Borland Caliber 11.0 Quiksoft EasyMail SMTP Object Buffer Overflows","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-08-28T16:57:02.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"25467","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25467"},{"name":"VU#281977","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/281977"},{"name":"24199","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24199"},{"name":"26639","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26639"},{"tags":["x_refsource_MISC"],"url":"http://retrogod.altervista.org/postcast-emsmtp_bof.html"},{"tags":["x_refsource_MISC"],"url":"https://community.ivanti.com/docs/DOC-50988"},{"name":"38335","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/38335"},{"name":"easymail-submittoexpress-bo(36307)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36307"},{"name":"4328","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4328"},{"name":"20130424 Borland Caliber 11.0 Quiksoft EasyMail SMTP Object Buffer Overflows","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4607","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"25467","refsource":"BID","url":"http://www.securityfocus.com/bid/25467"},{"name":"VU#281977","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/281977"},{"name":"24199","refsource":"SECUNIA","url":"http://secunia.com/advisories/24199"},{"name":"26639","refsource":"SECUNIA","url":"http://secunia.com/advisories/26639"},{"name":"http://retrogod.altervista.org/postcast-emsmtp_bof.html","refsource":"MISC","url":"http://retrogod.altervista.org/postcast-emsmtp_bof.html"},{"name":"https://community.ivanti.com/docs/DOC-50988","refsource":"MISC","url":"https://community.ivanti.com/docs/DOC-50988"},{"name":"38335","refsource":"OSVDB","url":"http://osvdb.org/38335"},{"name":"easymail-submittoexpress-bo(36307)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36307"},{"name":"4328","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4328"},{"name":"20130424 Borland Caliber 11.0 Quiksoft EasyMail SMTP Object Buffer Overflows","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2013-04/0220.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4607","datePublished":"2007-08-31T00:00:00.000Z","dateReserved":"2007-08-30T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.731Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-31 00:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gate_comm_software:postcast_server_pro:3.0.61:*:*:*:*:*:*:*","matchCriteriaId":"8E91CBDF-3CD9-47C8-9673-18955069A047"},{"vulnerable":true,"criteria":"cpe:2.3:a:quicksoft:easymail_objects:*:*:*:*:*:*:*:*","matchCriteriaId":"E740C74B-1390-465F-A620-25C5213414C3"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4607","Ordinal":"1","Title":"CVE-2007-4607","CVE":"CVE-2007-4607","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4607","Ordinal":"1","NoteData":"Buffer overflow in the EasyMailSMTPObj ActiveX control in emsmtp.dll 6.0.1 in the Quiksoft EasyMail SMTP Object, as used in Postcast Server Pro 3.0.61 and other products, allows remote attackers to execute arbitrary code via a long argument to the SubmitToExpress method, a different vulnerability than CVE-2007-1029. NOTE: this may have been fixed in version 6.0.3.15.","Type":"Description","Title":"CVE-2007-4607"},{"CveYear":"2007","CveId":"4607","Ordinal":"2","NoteData":"2007-08-30","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4607","Ordinal":"3","NoteData":"2018-08-28","Type":"Other","Title":"Modified"}]}}}