VDB
CVE-2006-6424
CVE-2006-6424
PUBLISHED
CVSS 9 CRITICAL
Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.
EPSS 69.21% · 98.7th percentile
Risk Scores
CVSS 2.0
9
EPSS Score
69.21%
98.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| novell | netmail | 0, 3.0.3a, 3.0.3a |
Timeline
- Dec 22, 2006 CVE Published
- May 9, 2010 PoC Published
- May 29, 2018 PoC Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 22, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
References
- VU#381161 third-party-advisory
- https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html url
- 2081 third-party-advisory
- 21725 vdb
- 20061223 ZDI-06-052: Novell NetMail NMAP STOR Buffer Overflow Vulnerability mailing-list
- ADV-2006-5134 vdb
- http://www.cirt.dk/advisories/cirt-48-advisory.txt url
- 1017437 vdb
- http://www.zerodayinitiative.com/advisories/ZDI-06-053.html url
- http://www.zerodayinitiative.com/advisories/ZDI-06-052.html url
- 21724 vdb
- VU#912505 third-party-advisory
- 23437 third-party-advisory
- 20061223 ZDI-06-053: Novell NetMail IMAP Verb Literal Heap Overflow Vulnerability mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2006-6424 advisory