Buffer Overflow Vulnerability in Tabs Mail Carrier by Tabs
CVE-2019-25646
Key Information:
- Vendor
Tabs
- Status
- Vendor
- CVE Published:
- 24 March 2026
Badges
What is CVE-2019-25646?
Tabs Mail Carrier version 2.5.1 is susceptible to a buffer overflow vulnerability that arises from the MAIL FROM SMTP command. By sending a specially crafted MAIL FROM parameter, remote attackers could gain control of the affected system. This is accomplished through connecting to the SMTP service on port 25 and providing an oversized buffer, which allows the attacker to overwrite the instruction pointer (EIP register). Such exploitation could lead to arbitrary code execution, including the capability to deploy a bind shell.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mail Carrier 2.5.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
