← Vulnerability feed

Vulnerability record · CVE-2006-6423 · published 12 December 2006

CVE-2006-6423: MailEnable IMAP Service Pre-Auth Stack Buffer Overflow

Mailenable · Mailenable Enterprise

MailEnable Professional and Enterprise IMAP service contains a stack-based buffer overflow reachable before authentication. A remote attacker can send a crafted command with an oversized parameter to corrupt the stack and potentially execute arbitrary code. The flaw affects multiple 1.x and 2.x branches and was fixed by the ME-10025 hotfix.

10.0 CVSS 2.0 High EPSS 71% · top 0.6%
10.0CVSS 2.0 base score
71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a long string, as addressed by the ME-10025 hotfix.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityPre-authentication remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability makes this an urgent patch target despite no KEV listing.

What it is

MailEnable Professional and Enterprise IMAP service contains a stack-based buffer overflow reachable before authentication. A remote attacker can send a crafted command with an oversized parameter to corrupt the stack and potentially execute arbitrary code. The flaw affects multiple 1.x and 2.x branches and was fixed by the ME-10025 hotfix.

Impact

Successful exploitation can give a remote unauthenticated attacker arbitrary code execution in the context of the IMAP service, leading to full compromise of the mail server. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

The IMAP service is network-reachable and the overflow is triggered by a pre-authentication command followed by a crafted parameter and long string, so no credentials or user interaction are required. Any host exposing the MailEnable IMAP listener is in scope.

Exploitation

The record is not listed in CISA KEV and no ransomware associations are documented. EPSS is high at roughly 0.707 (99.4th percentile), and references include vendor and Secunia advisories tagged Patch, but no public exploit code is confirmed in the supplied data.

What to do

  • Apply the vendor ME-10025 hotfix or upgrade to a fixed MailEnable build immediately.
  • Restrict network access to the IMAP service to trusted hosts or VPN where possible.
  • Place the mail server behind filtering that rejects malformed or oversized IMAP commands.
  • Monitor vendor advisories for the affected 1.x and 2.x branches and confirm the installed build is patched.
  • Segment the mail server so a compromise cannot pivot freely into other internal systems.

Detection

  • Inspect IMAP service logs for pre-authentication commands with unusually long parameters or malformed syntax.
  • Alert on crashes or restarts of the MailEnable IMAP service, which may indicate attempted exploitation.
  • Use network IDS signatures for oversized IMAP command parameters against the MailEnable listener.
  • Correlate inbound IMAP connections from unexpected external sources with service fault events.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6423 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6997Mailenable enterprise improper authentication vulnerabilityUnspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi…EPSS 1.8%10.0CVE-2006-6605Mailenable enterprise vulnerabilityStack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41,…EPSS 5.9%10.0CVE-2006-1792Mailenable enterprise vulnerabilityUnspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition bef…EPSS 1.8%10.0CVE-2005-2222Mailenable professional vulnerabilityUnknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.EPSS 1.4%9.3CVE-2006-5176Mailenable enterprise memory buffer overflow vulnerabilityBuffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the s…EPSS 5.4%9.3CVE-2006-5177Mailenable enterprise memory buffer overflow vulnerabilityThe NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vecto…EPSS 7.1%9.0CVE-2008-1276Mailenable enterprise memory buffer overflow vulnerabilityMultiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote a…EPSS 7.1%9.0CVE-2008-1277Mailenable enterprise improper input validation vulnerabilityThe IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial o…EPSS 8.3%

Source: NIST National Vulnerability Database (record CVE-2006-6423), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.