Vulnerability record · CVE-2005-3314 · published 18 November 2005
CVE-2005-3314: Novell NetMail IMAP daemon stack buffer overflow via long verb arguments
Novell · Netmail
The IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated attacker can send crafted IMAP commands to corrupt memory, which matters because the daemon is network-exposed and the flaw can lead to code execution.
Description
Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code via "long verb arguments."
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with a high EPSS score, though no confirmed in-the-wild exploitation or KEV listing.
What it is
The IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated attacker can send crafted IMAP commands to corrupt memory, which matters because the daemon is network-exposed and the flaw can lead to code execution.
Impact
An attacker can execute arbitrary code in the context of the IMAP daemon, potentially gaining control of the mail server and access to mail data or the underlying host.
Attack surface
Reachable over the network through the IMAP service (CVSS vector AV:N/AC:L/Au:N), requiring no authentication and no user interaction; the attacker only needs to send a malformed command with an oversized verb argument.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at 0.65657 (99.23rd percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Novell vendor patches referenced in the advisory (support.novell.com 2972665, 2972672, 2972673) or upgrade NetMail past 3.5.2.
- Restrict network access to the IMAP service to trusted hosts or VPN, and block it from the public internet where possible.
- Run the IMAP daemon with least privilege and isolate the mail server from other critical systems.
- Monitor vendor advisories for updated guidance if the affected product is still in use.
Detection
- Inspect IMAP server logs for malformed or unusually long verb arguments and repeated connection errors.
- Monitor for crashes or restarts of the NetMail IMAP daemon, which may indicate exploitation attempts.
- Use network IDS signatures for oversized IMAP command arguments targeting the service.
- Watch for unexpected child processes or outbound connections originating from the mail server host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3314 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-3314), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.