← Vulnerability feed

Vulnerability record · CVE-2006-6425 · published 27 December 2006

CVE-2006-6425: Novell NetMail IMAPD APPEND stack buffer overflow

Novell · Netmail

Novell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow reachable through the APPEND command. A remote authenticated IMAP user can corrupt the stack and potentially run arbitrary code on the mail server, making this a serious pre-auth-adjacent risk for any internet-facing NetMail deployment.

9.0 CVSS 2.0 High EPSS 58% · top 0.9%
9.0CVSS 2.0 base score
58%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
18References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via unspecified vectors involving the APPEND command.

AV:N/AC:L/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote code execution with a complete confidentiality, integrity and availability impact, tempered only by the requirement for a valid IMAP account and the age of the affected product.

What it is

Novell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow reachable through the APPEND command. A remote authenticated IMAP user can corrupt the stack and potentially run arbitrary code on the mail server, making this a serious pre-auth-adjacent risk for any internet-facing NetMail deployment.

Impact

An attacker with a valid IMAP account gains the ability to execute arbitrary code in the context of the IMAPD service, which typically runs with elevated privileges on the mail host. That can lead to full server compromise, mail store access and lateral movement into the internal network.

Attack surface

Reached over the network via the IMAP service (AV:N) with low attack complexity (AC:L); the vector requires authentication (Au:S) but no user interaction. The flaw is triggered by the APPEND command, so any account able to issue IMAP commands can attempt it.

Exploitation

Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is 0.579 (99th percentile), indicating a high modeled likelihood of exploitation activity. Multiple vendor and ZDI advisories with Patch tags exist, so weaponized or PoC code may circulate even though none is confirmed here.

What to do

  • Upgrade Novell NetMail to 3.52e FTF2 or later; apply the vendor patch referenced in the Novell support and ZDI advisories.
  • If patching is not immediately possible, restrict IMAP access to trusted networks or VPN and disable the service where it is not required.
  • Enforce strong unique credentials and least privilege on IMAP accounts to reduce the pool of authenticated users who can reach the vulnerable APPEND path.
  • Monitor vendor channels for an updated NetMail release, since the affected product line is legacy and may not receive further fixes.

Detection

  • Inspect IMAP server logs for APPEND commands with unusually long argument strings or malformed literals targeting IMAPD.
  • Alert on IMAPD process crashes, restarts or core dumps on NetMail hosts, which can indicate a failed overflow attempt.
  • Watch for unexpected child processes, outbound connections or file writes originating from the IMAPD service account.
  • Use network IDS signatures for oversized IMAP APPEND requests against NetMail servers.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2616Novell netmail vulnerabilityStack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to …EPSS 6.0%9.0CVE-2006-6424Novell NetMail IMAPD and NMAP daemon buffer overflows allow remote code executionNovell NetMail before 3.52e FTF2 contains multiple buffer overflows: a heap overflow in IMAPD triggered by appending literals to certain IMAP verbs d…EPSS 60%analysed7.5CVE-2005-3314Novell NetMail IMAP daemon stack buffer overflow via long verb argumentsThe IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated …EPSS 66%analysed7.5CVE-2005-1757Novell netmail vulnerabilityBuffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.EPSS 3.1%7.5CVE-2005-1758Novell netmail vulnerabilityBuffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.EPSS 16%7.5CVE-2002-0996Novell netmail vulnerabilityMultiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbi…EPSS 3.5%6.8CVE-2007-6302Novell netmail memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote att…EPSS 5.6%6.8CVE-2007-1350Novell netmail vulnerabilityStack-based buffer overflow in webadmin.exe in Novell NetMail 3.5.2 allows remote attackers to execute arbitrary code via a long username during HTTP…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2006-6425), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.