Back

CVE-2004-2726

HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which allows remote attackers to cause a denial of service (null dereference and application crash). NOTE: This is a different vulnerability than CVE-2005-1348.

Published: Dec 31, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (1)

Vendor Product Version
mailenable mailenable 1.18

GitHub Security Advisory GHSA-pw85-4jwp-m329

HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the...

Risk Scores

CVSS Score 5.0 / 10
EPSS Score 2.82%

Top 15% most likely to be exploited

Threat Score 20.8 / 100

Data Sources

NVD EPSS GitHub