CVE-2019-25364: Tabslab Mailcarrier

Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.

MailCarrier 2.51 contains a buffer overflow vulnerability in the POP3 USER command that allows remote attackers to execute arbitrary code. Attackers can send a crafted oversized buffer to the POP3 service, overwriting memory and potentially gaining remote system access.

Affected products

  • Tabslab Mailcarrier: version 2.51 only

Published 2026-02-18. Last modified 2026-06-17.