Executive brief
Qualitia Active! mail 6 contains a stack-based buffer overflow vulnerability (CWE-121) due to improper handling of specially crafted requests. A remote, unauthenticated attacker can exploit this to execute arbitrary code or cause a denial-of-service (DoS) condition.
Affected products
- Qualitia Active! mail 6 BuildInfo: 6.60.05008561 and earlier
Timeline
- 2025-04-18: disclosed: Initial disclosure by JPCERT/CC and vendor advisory published.
- 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.