← Vulnerability feed

Vulnerability record · CVE-2006-2502 · published 22 May 2006

CVE-2006-2502: Cyrus IMAPD pop3d stack buffer overflow via long USER command

Cyrus · Imapd

Cyrus IMAPD 2.3.2 contains a stack-based buffer overflow in pop3d when the popsubfolders option is enabled. A remote attacker can send an overly long USER command to overwrite stack memory and potentially execute arbitrary code. The flaw matters because POP3 is typically exposed to untrusted networks, and the affected configuration is a documented option rather than an unusual setup.

5.1 CVSS 2.0 Medium EPSS 53% · top 1.0%
5.1CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allows remote attackers to execute arbitrary code via a long USER command.

AV:N/AC:H/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution is possible in a network-facing service, and public exploit references plus a high EPSS score raise the likelihood of attempted exploitation despite the medium CVSS 2.0 score.

What it is

Cyrus IMAPD 2.3.2 contains a stack-based buffer overflow in pop3d when the popsubfolders option is enabled. A remote attacker can send an overly long USER command to overwrite stack memory and potentially execute arbitrary code. The flaw matters because POP3 is typically exposed to untrusted networks, and the affected configuration is a documented option rather than an unusual setup.

Impact

Successful exploitation could allow a remote unauthenticated attacker to execute arbitrary code with the privileges of the pop3d process. At minimum, a crash or denial of service is likely from the overflow.

Attack surface

The flaw is reached over the network through the POP3 service by sending a crafted USER command; the CVSS vector AV:N/Au:N indicates no authentication is required. No user interaction is indicated by the description or vector.

Exploitation

Public exploit references exist in the Full Disclosure and SecurityFocus BID entries, and EPSS is high at roughly 0.53 (99th percentile), but the CVE is not listed in CISA KEV, so active exploitation in the wild is not confirmed by that source.

What to do

  • Upgrade Cyrus IMAPD to a version later than 2.3.2 that fixes the pop3d overflow, or apply the vendor patch for this issue.
  • If POP3 is not required, disable the pop3d service entirely.
  • If popsubfolders is not needed, disable that option to remove the vulnerable code path.
  • Restrict POP3 access to trusted networks or VPN users and block it from the public internet where feasible.
  • Run pop3d with least privilege and monitor for crashes or abnormal process termination.

Detection

  • Inspect POP3 server logs for unusually long USER commands or malformed POP3 sessions.
  • Monitor for pop3d process crashes, core dumps, or unexpected restarts.
  • Use network IDS signatures for oversized POP3 USER commands against the affected service.
  • Alert on unexpected outbound connections or child processes spawned by pop3d.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2502 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-2502), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.