← Vulnerability feed

Vulnerability record · CVE-2006-6424 · published 27 December 2006

CVE-2006-6424: Novell NetMail IMAPD and NMAP daemon buffer overflows allow remote code execution

Novell · Netmail

Novell NetMail before 3.52e FTF2 contains multiple buffer overflows: a heap overflow in IMAPD triggered by appending literals to certain IMAP verbs during command continuation requests, and a stack overflow in the NMAP daemon via crafted STOR command arguments. Both flaws allow remote code execution, making them serious for any internet-exposed mail server.

9.0 CVSS 2.0 High EPSS 60% · top 0.9%
9.0CVSS 2.0 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with complete confidentiality, integrity, and availability impact, though authentication is required and no confirmed in-the-wild exploitation is documented.

What it is

Novell NetMail before 3.52e FTF2 contains multiple buffer overflows: a heap overflow in IMAPD triggered by appending literals to certain IMAP verbs during command continuation requests, and a stack overflow in the NMAP daemon via crafted STOR command arguments. Both flaws allow remote code execution, making them serious for any internet-exposed mail server.

Impact

An attacker can execute arbitrary code on the mail server, likely with the privileges of the IMAPD or NMAP daemon process, leading to full compromise of the messaging service and its data.

Attack surface

Reachable over the network via the IMAP and NMAP service ports; the CVSS vector indicates authentication is required (Au:S), and no user interaction is needed beyond sending crafted protocol commands.

Exploitation

Not listed in CISA KEV and no public exploit tags in the references, but EPSS is very high (0.59, 99th percentile), suggesting elevated likelihood of exploitation activity.

What to do

  • Upgrade Novell NetMail to version 3.52e FTF2 or later, applying the vendor patch referenced in the advisories.
  • Restrict network access to IMAP and NMAP ports to trusted hosts or VPN where possible.
  • Disable or block the NMAP daemon if it is not required for messaging operations.
  • Monitor vendor and CERT/CC advisories for any updated guidance on the affected components.

Detection

  • Inspect IMAPD logs for malformed command continuation requests or unusual literal appends to IMAP verbs.
  • Monitor NMAP daemon logs for STOR commands with abnormally long or crafted arguments.
  • Watch for unexpected process crashes or restarts of IMAPD or NMAP services that could indicate exploitation attempts.
  • Use network IDS signatures for buffer overflow patterns against IMAP and NMAP traffic if available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/23437 PatchVendor Advisory
http://securityreason.com/securityalert/2081
http://securitytracker.com/id?1017437 Patch
http://www.cirt.dk/advisories/cirt-48-advisory.txt PatchVendor Advisory
http://www.kb.cert.org/vuls/id/381161 US Government Resource
http://www.kb.cert.org/vuls/id/912505 US Government Resource
http://www.securityfocus.com/archive/1/455201/100/0/threaded
http://www.securityfocus.com/archive/1/455202/100/0/threaded
http://www.securityfocus.com/bid/21724
http://www.securityfocus.com/bid/21725
http://www.vupen.com/english/advisories/2006/5134
http://www.zerodayinitiative.com/advisories/ZDI-06-052.html PatchVendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-053.html PatchVendor Advisory
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html Patch
http://secunia.com/advisories/23437 PatchVendor Advisory
http://securityreason.com/securityalert/2081
http://securitytracker.com/id?1017437 Patch
http://www.cirt.dk/advisories/cirt-48-advisory.txt PatchVendor Advisory
http://www.kb.cert.org/vuls/id/381161 US Government Resource
http://www.kb.cert.org/vuls/id/912505 US Government Resource
http://www.securityfocus.com/archive/1/455201/100/0/threaded
http://www.securityfocus.com/archive/1/455202/100/0/threaded
http://www.securityfocus.com/bid/21724
http://www.securityfocus.com/bid/21725
http://www.vupen.com/english/advisories/2006/5134
http://www.zerodayinitiative.com/advisories/ZDI-06-052.html PatchVendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-06-053.html PatchVendor Advisory
https://secure-support.novell.com/KanisaPlatform/Publishing/134/3096026_f.SAL_Public.html Patch

Track CVE-2006-6424 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2616Novell netmail vulnerabilityStack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to …EPSS 6.0%9.0CVE-2006-6425Novell NetMail IMAPD APPEND stack buffer overflowNovell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow reachable through the APPEND command. A remote authenti…EPSS 58%analysed7.5CVE-2005-3314Novell NetMail IMAP daemon stack buffer overflow via long verb argumentsThe IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated …EPSS 66%analysed7.5CVE-2005-1757Novell netmail vulnerabilityBuffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.EPSS 3.1%7.5CVE-2005-1758Novell netmail vulnerabilityBuffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.EPSS 16%7.5CVE-2002-0996Novell netmail vulnerabilityMultiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbi…EPSS 3.5%6.8CVE-2007-6302Novell netmail memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote att…EPSS 5.6%6.8CVE-2007-1350Novell netmail vulnerabilityStack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2006-6424), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.