Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages.
https://exchange.xforce.ibmcloud.com/vulnerabilities/38587
https://exchange.xforce.ibmcloud.com/vulnerabilities/38586
http://www.securityfocus.com/bid/26514
http://www.code-crafters.com/abilitymailserver/updatelog.html