← Vulnerability feed

Vulnerability record · CVE-2006-6761 · published 27 December 2006

CVE-2006-6761: Novell NetMail IMAPD SUBSCRIBE stack buffer overflow

Novell · Netmail

Novell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow triggered by a long argument to the IMAP SUBSCRIBE command. A remote party who can authenticate to the IMAP service can overflow the stack and potentially execute arbitrary code in the daemon's context.

6.5 CVSS 2.0 Medium EPSS 53% · top 1.0%
6.5CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the IMAP daemon (IMAPD) in Novell NetMail before 3.52e FTF2 allows remote authenticated users to execute arbitrary code via a long argument to the SUBSCRIBE command.

AV:N/AC:L/Au:S/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote code execution in a mail server is severe, and the high EPSS score plus an exploit-tagged reference raise the likelihood of attempted exploitation despite the authentication requirement.

What it is

Novell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow triggered by a long argument to the IMAP SUBSCRIBE command. A remote party who can authenticate to the IMAP service can overflow the stack and potentially execute arbitrary code in the daemon's context.

Impact

An authenticated remote attacker can corrupt the stack and potentially execute arbitrary code with the privileges of the IMAPD process, leading to full compromise of the mail server.

Attack surface

Reached over the network through the IMAP service by sending a crafted SUBSCRIBE command; the CVSS vector (AV:N/AC:L/Au:S) indicates authentication is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV and no ransomware associations are recorded; EPSS is high (0.53112, 98.9th percentile) and one Secunia reference carries an Exploit tag, but no public exploit code is confirmed in the record.

What to do

  • Upgrade Novell NetMail to 3.52e FTF2 or later, which the vendor references as the fixed release.
  • Restrict IMAP access to trusted networks and require strong authentication to limit who can reach the SUBSCRIBE command.
  • Monitor IMAP logs for malformed or oversized SUBSCRIBE arguments and alert on repeated failures.
  • If NetMail is end-of-life or unsupported, migrate to a maintained mail platform or isolate the service behind a filtering proxy.

Detection

  • Inspect IMAP server logs for SUBSCRIBE commands with unusually long mailbox arguments.
  • Deploy network IDS/IPS signatures for oversized SUBSCRIBE requests to the IMAP port.
  • Monitor the IMAPD process for crashes, restarts, or unexpected child processes that could indicate exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6761 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2616Novell netmail vulnerabilityStack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to …EPSS 6.0%9.0CVE-2006-6424Novell NetMail IMAPD and NMAP daemon buffer overflows allow remote code executionNovell NetMail before 3.52e FTF2 contains multiple buffer overflows: a heap overflow in IMAPD triggered by appending literals to certain IMAP verbs d…EPSS 60%analysed9.0CVE-2006-6425Novell NetMail IMAPD APPEND stack buffer overflowNovell NetMail's IMAP daemon (IMAPD) before 3.52e FTF2 contains a stack-based buffer overflow reachable through the APPEND command. A remote authenti…EPSS 58%analysed7.5CVE-2005-3314Novell NetMail IMAP daemon stack buffer overflow via long verb argumentsThe IMAP daemon in Novell NetMail 3.5.2 contains a stack-based buffer overflow (CWE-119) triggered by long verb arguments. A remote, unauthenticated …EPSS 66%analysed7.5CVE-2005-1757Novell netmail vulnerabilityBuffer overflow in the Modweb agent for Novell NetMail 3.52 before 3.52C, when renaming folders, may allow attackers to execute arbitrary code.EPSS 3.1%7.5CVE-2005-1758Novell netmail vulnerabilityBuffer overflow in the IMAP command continuation function in Novell NetMail 3.52 before 3.52C may allow remote attackers to execute arbitrary code.EPSS 16%7.5CVE-2002-0996Novell netmail vulnerabilityMultiple buffer overflows in Novell NetMail (NIMS) 3.0.3 before 3.0.3C allows remote attackers to cause a denial of service and possibly execute arbi…EPSS 3.5%6.8CVE-2007-6302Novell netmail memory buffer overflow vulnerabilityMultiple heap-based buffer overflows in avirus.exe in Novell NetMail 3.5.2 before Messaging Architects M+NetMail 3.52f (aka 3.5.2F) allows remote att…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2006-6761), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.