SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-6424

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2)…

HIGH 9.0EPSS 59.5%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 59.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Multiple buffer overflows in Novell NetMail before 3.52e FTF2 allow remote attackers to execute arbitrary code (1) by appending literals to certain IMAP verbs when specifying command continuation requests to IMAPD, resulting in a heap overflow; and (2) via crafted arguments to the STOR command to the Network Messaging Application Protocol (NMAP) daemon, resulting in a stack overflow.

CVSS 2.0
9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS
59.47% probability · 99th percentile
CISA KEV
Not listed
Affected
novell/netmail
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.