← Vulnerability feed

Vulnerability record · CVE-2006-3840 · published 27 July 2006

CVE-2006-3840: Iss blackice pc protection vulnerability

Iss · Blackice Pc Protection

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

5.0 CVSS 2.0 Medium EPSS 2.4% · top 16.8% CWE-399 · CWE-399
5.0CVSS 2.0 base score
2.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
10Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Affected products

10 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3840 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2007-2690Iss proventia a series xpu vulnerabilityMultiple IBM ISS Proventia Series products, including the A, G, and M series, do not properly handle certain full-width and half-width Unicode charac…EPSS 2.0%7.5CVE-2004-0362ISS PAM ICQ Parsing Stack Buffer Overflows Allow Remote Code ExecutionThe ISS Protocol Analysis Module (PAM) used in RealSecure, Proventia and BlackICE products contains multiple stack-based buffer overflows in its ICQ …EPSS 73%analysed7.5CVE-2004-0193Iss blackice agent server vulnerabilityHeap-based buffer overflow in the ISS Protocol Analysis Module (PAM), as used in certain versions of RealSecure Network 7.0 and Server Sensor 7.0, Pr…EPSS 8.0%7.2CVE-2005-2711Iss blackice agent server vulnerabilityISS BlackIce 3.6, as used in multiple products including BlackICE PC Protection, Server Protection, Agent for Server, and RealSecure Desktop 3.6 and …EPSS 0.37%7.1CVE-2004-1714Iss blackice pc protection incorrect permission assignment vulnerabilityBlackICE PC Protection and Server Protection installs (1) firewall.ini, (2) blackice.ini, (3) sigs.ini and (4) protect.ini with Everyone Full Control…EPSS 0.85%4.6CVE-2006-4541Iss blackice pc protection improper input validation vulnerabilityRapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a …EPSS 0.73%4.6CVE-2006-3999Iss blackice pc protection vulnerabilityISS BlackICE PC Protection 3.6.cpj, 3.6.cpiE, and possibly earlier versions do not properly monitor the integrity of the pamversion.dll BlackICE libr…EPSS 0.33%4.6CVE-2004-2125Iss blackice agent server vulnerabilityBuffer overflow in blackd.exe for BlackICE PC Protection 3.6 and other versions before 3.6.ccb, with application protection off, allows local users t…EPSS 0.42%

Source: NIST National Vulnerability Database (record CVE-2006-3840), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.