CVE-2003-0264 is a set of remotely reachable stack-based buffer overflows in SLMail 5.1.0.4420. The flaws are triggered by oversized SMTP EHLO or XTRN arguments, an oversized POPPASSWD string, or an oversized password supplied to the POP3 PASS command. Malformed input can overwrite the saved instruction pointer and redirect execution to attacker-controlled code.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a training-oriented but functional exploit development walkthrough for CVE-2003-0264, a stack-based buffer overflow in the POP3 PASS command handler of SLMail 5.5 and earlier on Windows. It is not part of a larger exploit framework. The repository contains 13 files total, with 7 Python exploit scripts and several Markdown documents explaining the environment, methodology, and learning context. The exploit chain is organized as a sequence of standalone Python 3 scripts under Vulnerability/Exploit/: 01Python3Connection.py validates POP3 connectivity and USER/PASS interaction; 02Python3Fuzzing.py incrementally increases PASS length to trigger a crash; 03Python3EIPOffsetDiscovery.py sends a cyclic pattern to determine the exact EIP overwrite offset; 04Python3ControlEIP.py confirms control of EIP using offset 2606 and marker BBBB; 05Python3FindBadChars.py places all byte values after EIP to identify bad characters; 06Python3JMPESP.py overwrites EIP with a hardcoded JMP ESP gadget from SLMFC.DLL at 0x5f4a358f and uses NOP/INT3 bytes to verify execution reaches the stack; 07Python3Shellcode.py delivers the final payload with the same gadget, a short NOP sled, and embedded Windows shellcode. Main exploit capability: remote unauthenticated code execution over the network via POP3 on TCP port 110. The code consistently connects to a target IP (default 127.0.0.1), receives the POP3 banner, sends USER username, then sends a malicious PASS argument. The final payload is a classic stack overflow layout: 2606 bytes of padding, EIP overwrite, NOP sled, and shellcode. The included documentation states the known bad characters are \x00, \x0a, and \x0d, and the final shellcode is intended to provide a reverse shell. The methodology also references msfvenom generation of a windows/shell_reverse_tcp payload and a listener on 192.168.1.10:443, though the embedded shellcode itself is hardcoded in the final script. Fingerprintable targets and artifacts include the POP3 service on TCP/110, the default loopback target 127.0.0.1, the vulnerable PASS command, and the Windows module C:\WINDOWS\SYSTEM32\SLMFC.DLL containing the reusable JMP ESP gadget. Overall, the repository’s purpose is educational exploit development for a real historical RCE vulnerability, but the included code is sufficient to reproduce the crash and achieve code execution in a lab environment.
This repository contains a single Metasploit exploit module targeting a buffer overflow vulnerability in the Seattle Lab Mail 5.5 POP3 server (CVE-2003-0264). The exploit works by sending an overly long password via the PASS command to the POP3 service running on TCP port 110. The buffer overflow allows the attacker to overwrite the return address with a pointer to a 'jmp esp' instruction in SLMFC.DLL, enabling execution of arbitrary code supplied as a payload. The module is written in Ruby and leverages Metasploit's payload system, allowing for customizable payloads such as reverse shells or command execution. The exploit is operational and can be used to gain remote code execution on vulnerable systems. The only endpoints referenced are the POP3 service port (110) and the SLMFC.DLL file used for the exploit's return address. The module is self-contained and does not reference any external network resources beyond the target POP3 service.
This repository contains a Python exploit script (slmail-into-shell.py) targeting the buffer overflow vulnerability in SLmail 5.5 (CVE-2003-0264). The exploit leverages a crafted payload to overflow the buffer in the POP3 PASS command, overwriting the EIP with a JMP ESP address from a non-ASLR module, and executes a reverse shell payload generated by msfvenom. The script uses pwntools for network interaction and threading to simultaneously launch the exploit and listen for a reverse shell connection. The README provides usage context and an example of successful exploitation, showing SYSTEM-level shell access on the target. The exploit is operational, providing a working reverse shell if the target is vulnerable and reachable. The main fingerprintable endpoints are the target's IP and POP3 port, and the attacker's listener port. The repository is structured simply, with a single exploit script and a README for documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Stack-based buffer-overflow vulnerabilities in SLMail 5.1.0.4420 affecting EHLO, XTRN, POPPASSWD, and POP3 PASS handling. Supplying oversized inputs can overwrite EIP and enable arbitrary code execution.
A stack-based buffer overflow vulnerability in SLMAIL 5.5 POP3 Server triggered via the PASS/password parameter during authentication, enabling remote code execution.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.