Back to Database
Status published
Critical
CVE-2007-2188
eXtremail 2.1.1 and earlier does not verify the ID field...
Vulnerability Description
eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-2188
Credits & Attribution
No credits recorded in the NVD database.
References
More from extremail
View All →CVE-2007-5467
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers...
Critical
10
CVE-2007-5466
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote...
Critical
10
CVE-2007-2187
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote...
Critical
10
CVE-2006-6926
Buffer overflow in eXtremail 2.1 has unknown impact and attack...
Critical
10
CVE-2004-0332
Extremail 1.5.9 does not check passwords correctly when they are...
Critical
10
Affected Vendor
extremail
View all reports →Affected Software
extremail
Vulnerable Versions:
2.1, 2.1.1
Timeline
Official Publish:
April 24th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.