Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or application crash) or execute arbitrary code via a long argument to the (1) MAIL FROM or (2) RCPT TO command.
https://www.exploit-db.com/exploits/2650
https://exchange.xforce.ibmcloud.com/vulnerabilities/29803