CVE-2019-25646Disclosure(tabslab / mailcarrier)

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a crafted MAIL FROM parameter. Attackers can connect to the SMTP service on port 25 and send a malicious MAIL FROM command with an oversized buffer to overwrite the EIP register and execute a bind shell payload.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mailcarrier

Threat summary

  • 4 mentions across 1 observed day

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
mailcarrier

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-24: 4Technical Details · 2026-03-24: 403-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2019-25646 Tabs Mail Carrier 2.5.1 contains a buffer overflow vulnerability in the MAIL FROM SMTP command that allows remote attackers to execute arbitrary code by sending a cra… https://www.cve.org/CVERecord?id=CVE-2019-25646

    Post summary

    The text discloses a buffer overflow in Tabs Mail Carrier 2.5.1 that allows remote code execution, but it provides no PoC, exploit, or mitigation details.

    00010156
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2019-25646 - Tabs Mail Carrier 2.5.1 Buffer Overflow via MAIL FROM Intel Report: https://ift.tt/QyNm3hY

    Post summary

    The post announces a buffer‑overflow vulnerability (CVE‑2019‑25646) in Tabs Mail Carrier 2.5.1, linking to an Intel report, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000019
    286 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2019-25646: CRITICAL] Tabs Mail Carrier 2.5.1 has a critical buffer overflow flaw in the MAIL FROM SMTP command, enabling remote hackers to run arbitrary code. They exploit this to execute a bind shell ...#cve,CVE-2019-25646,#cybersecurity https://cvefind.com/CVE-2019-25646

    Post summary

    The post reports a critical buffer overflow vulnerability (CVE‑2019‑25646) in Tabs Mail Carrier 2.5.1 that allows remote code execution via the MAIL FROM SMTP command, but it lacks proof‑of‑concept, exploit code, or patch information.

    0000038
    606 followersView on X
  • 0day Signal@0dayPublishing
    General

    🚨 CVE-2019-25646: Tabs Mail Carrier 2.5.1 Buffer O... Stack smashing SMTP servers in 2019 with oversized MAIL FROM commands - classic EIP overwrite leading to remote shells ... https://zerodaysignal.com/vulnerability/CVE-2019-25646 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet discusses CVE-2019-25646, noting a buffer overflow in Tabs Mail Carrier that allows remote shells via oversized MAIL FROM commands, yet provides no PoC, patch, or evidence of ongoing exploitation.

    0000038
    164 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptabslabmailcarrier2.5.1--

Explore more