peter bassill · operator
$ cve CVE-2006-6423 JSON

CVE-2006-6423 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 70.7% (pctl 99)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through 1.84, and Enterprise Edition 1.1 through 1.41 allows remote attackers to execute arbitrary code via a pre-authentication command followed by a crafted parameter and a long string, as addressed by the ME-10025 hotfix.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS70.71% — more likely to be exploited than 99% of all CVEs
On CISA KEVno
Public exploityes
Published2006-12-12
Last modified2026-06-16

Affected (2)

VendorProduct
mailenablemailenable enterprise
mailenablemailenable professional

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD