axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial of service (NULL dereference and application crash) via a base64-encoded "*\x00" sequence on the imap port (143/tcp).
https://www.exploit-db.com/exploits/3290
https://exchange.xforce.ibmcloud.com/vulnerabilities/32345
http://www.securityfocus.com/bid/22473