← Vulnerability feed

Vulnerability record · CVE-2006-0992 · published 14 April 2006

CVE-2006-0992: Novell GroupWise Messenger Accept-Language stack buffer overflow

Novell · Groupwise Messenger

Novell GroupWise Messenger before 2.0 Public Beta 2 contains a stack-based buffer overflow triggered by a long Accept-Language value that lacks a comma or semicolon. The flaw is remotely reachable over the network without authentication and can lead to arbitrary code execution on the affected client or service.

10.0 CVSS 2.0 High EPSS 73% · top 0.6%
10.0CVSS 2.0 base score
73%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
24References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 score is 10.0 with network reachability, no authentication, and complete impact, and public exploit code exists despite no KEV listing.

What it is

Novell GroupWise Messenger before 2.0 Public Beta 2 contains a stack-based buffer overflow triggered by a long Accept-Language value that lacks a comma or semicolon. The flaw is remotely reachable over the network without authentication and can lead to arbitrary code execution on the affected client or service.

Impact

A remote attacker can execute arbitrary code in the context of the vulnerable GroupWise Messenger process, potentially gaining full control of the affected system. The CVSS 2.0 vector indicates complete confidentiality, integrity, and availability impact.

Attack surface

The vulnerability is reached over the network (AV:N) with low complexity and no authentication required (AC:L/Au:N). No user interaction is indicated by the vector, though the description suggests the crafted Accept-Language value is processed by the messenger component.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.72833, 99.4th percentile) and public references include an Exploit-DB entry and a Metasploit blog post, indicating public exploit activity.

What to do

  • Upgrade Novell GroupWise Messenger to version 2.0 Public Beta 2 or later as directed by the vendor patch references.
  • Apply the vendor patch referenced in the Novell support and ZDI advisories.
  • Restrict network access to GroupWise Messenger services to trusted hosts or segments where feasible.
  • Monitor for and block malformed Accept-Language headers containing unusually long values without comma or semicolon delimiters.
  • Retire or isolate unsupported GroupWise Messenger versions that cannot be patched.

Detection

  • Inspect network traffic or logs for Accept-Language header values that are abnormally long or lack comma/semicolon delimiters.
  • Monitor GroupWise Messenger process crashes or unexpected restarts that could indicate exploitation attempts.
  • Use IDS/IPS signatures for known exploit patterns targeting the Accept-Language parsing path.
  • Review endpoint telemetry for suspicious child processes or code execution originating from the GroupWise Messenger process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-0992 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-0992), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.