The imap4d server for GNU Mailutils 0.5 and 0.6, and other versions before 0.6.90, allows authenticated remote users to cause a denial of service (CPU consumption) via a large range value in the FETCH command.
http://www.securityfocus.com/bid/13765
http://www.idefense.com/application/poi/display?id=247&type=vulnerabilities
http://www.debian.org/security/2005/dsa-732