← Vulnerability feed

Vulnerability record · CVE-2006-4364 · published 27 August 2006

CVE-2006-4364: MDaemon POP3 server heap buffer overflow via USER and APOP commands

AAlt N · Mdaemon

Alt-N MDaemon before 9.0.6 contains multiple heap-based buffer overflows in its POP3 server. Long strings containing '@' characters in the USER and APOP commands overflow heap buffers, crashing the daemon and potentially allowing code execution.

5.0 CVSS 2.0 Medium EPSS 57% · top 1.0%
5.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings that contain '@' characters in the (1) USER and (2) APOP commands.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote unauthenticated heap overflow with public exploit code and very high EPSS, though the CVSS impact is limited to partial availability loss.

What it is

Alt-N MDaemon before 9.0.6 contains multiple heap-based buffer overflows in its POP3 server. Long strings containing '@' characters in the USER and APOP commands overflow heap buffers, crashing the daemon and potentially allowing code execution.

Impact

A remote unauthenticated attacker can crash the POP3 daemon, causing denial of service, and may be able to execute arbitrary code in the server process context.

Attack surface

Reachable over the network through the POP3 service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is high at 0.56653 (99th percentile) and public references are tagged Exploit, including an Exploit-DB entry, indicating exploit code is publicly available.

What to do

  • Upgrade MDaemon to version 9.0.6 or later, which the vendor release notes and advisory address.
  • If immediate upgrade is not possible, restrict POP3 access to trusted networks or disable the POP3 service where unused.
  • Place the POP3 service behind a filtering proxy or IPS that rejects malformed USER and APOP commands containing long '@' strings.
  • Monitor vendor advisories for any follow-up fixes and verify the installed MDaemon build against the fixed version.

Detection

  • Inspect POP3 server logs for USER or APOP commands containing unusually long strings or embedded '@' characters.
  • Monitor for repeated MDaemon POP3 daemon crashes or restarts that correlate with inbound POP3 traffic.
  • Use network IDS signatures for oversized POP3 USER/APOP arguments and alert on anomalous command lengths.
  • Track process crashes of the MDaemon POP3 service and correlate with source IPs for triage.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-4364 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-5709Alt-n mdaemon vulnerabilityUnspecified vulnerability in WorldClient in Alt-N Technologies MDaemon before 9.50 has unknown impact and attack vectors related to a "JavaScript exp…EPSS 1.6%9.0CVE-2003-1470Alt-n mdaemon memory buffer overflow vulnerabilityBuffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbit…EPSS 5.0%7.5CVE-2006-5708Alt-n mdaemon uncontrolled resource consumption vulnerabilityMultiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of servic…EPSS 1.0%7.5CVE-2006-2646Alt-n mdaemon vulnerabilityBuffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins…EPSS 4.6%7.5CVE-2005-4266Alt-n mdaemon vulnerabilityWorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated wi…EPSS 1.3%7.5CVE-2003-1200Alt-N MDaemon FORM2RAW.exe stack buffer overflow via From parameterFORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 contains a stack-based buffer overflow reachable through a long From parameter passed to Form2Raw.c…EPSS 65%analysed7.5CVE-2000-1020Alt-n mdaemon vulnerabilityHeap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary command…EPSS 2.3%7.5CVE-2000-1021Alt-n mdaemon vulnerabilityHeap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands …EPSS 3.8%

Source: NIST National Vulnerability Database (record CVE-2006-4364), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.