Blue Coat Systems Inc. WinProxy before 6.1a allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of packets with 0xFF characters to the Telnet port (TCP 23), which corrupts the heap.
http://www.winproxy.com/products/relnotes.asp
http://www.vupen.com/english/advisories/2006/0065
http://www.securityfocus.com/bid/16149
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=365
http://securitytracker.com/id?1015442