{"api_version":"1","generated_at":"2026-07-23T09:41:53+00:00","cve":"CVE-2006-6291","urls":{"html":"https://cve.report/CVE-2006-6291","api":"https://cve.report/api/cve/CVE-2006-6291.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6291","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6291"},"summary":{"title":"CVE-2006-6291","description":"Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-05 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:L/Au:S/C:N/I:N/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:C","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30614","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["VDB Entry"],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4778","name":"http://www.vupen.com/english/advisories/2006/4778","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.mailenable.com/hotfix/","name":"http://www.mailenable.com/hotfix/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"MailEnable™ - Hot Fixes Download Page","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2006-71/advisory/","name":"http://secunia.com/secunia_research/2006-71/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MailEnable IMAP Service Two Vulnerabilities - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21362","name":"http://www.securityfocus.com/bid/21362","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"MailEnable IMAP Service Multiple Buffer Overflow Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/453118/100/100/threaded","name":"http://www.securityfocus.com/archive/1/453118/100/100/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017319","name":"http://securitytracker.com/id?1017319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - MailEnable IMAP Bugs Let Remote Authenticated Users Deny Service and Potentially Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23080","name":"http://secunia.com/advisories/23080","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"MailEnable IMAP Service Two Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017276","name":"http://securitytracker.com/id?1017276","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"SecurityTracker.com Archives - MailEnable Buffer Overflow in IMAP Service May Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6291","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6291","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6291","vulnerable":"1","versionEndIncluding":"1.40","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6291","vulnerable":"1","versionEndIncluding":"1.83","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6291","vulnerable":"1","versionEndIncluding":"2.33","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"enterprise","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6291","vulnerable":"1","versionEndIncluding":"2.33","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mailenable","cpe5":"mailenable","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"professional","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:19:35.214Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1017276","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017276"},{"name":"ADV-2006-4778","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4778"},{"name":"23080","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23080"},{"name":"21362","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21362"},{"name":"1017319","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017319"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.mailenable.com/hotfix/"},{"name":"20061130 Secunia Research: MailEnable IMAP Service Two Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/453118/100/100/threaded"},{"name":"mailenable-meimaps-bo(30614)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30614"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2006-71/advisory/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1017276","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017276"},{"name":"ADV-2006-4778","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4778"},{"name":"23080","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23080"},{"name":"21362","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21362"},{"name":"1017319","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017319"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.mailenable.com/hotfix/"},{"name":"20061130 Secunia Research: MailEnable IMAP Service Two Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/453118/100/100/threaded"},{"name":"mailenable-meimaps-bo(30614)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30614"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2006-71/advisory/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6291","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1017276","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017276"},{"name":"ADV-2006-4778","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4778"},{"name":"23080","refsource":"SECUNIA","url":"http://secunia.com/advisories/23080"},{"name":"21362","refsource":"BID","url":"http://www.securityfocus.com/bid/21362"},{"name":"1017319","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017319"},{"name":"http://www.mailenable.com/hotfix/","refsource":"CONFIRM","url":"http://www.mailenable.com/hotfix/"},{"name":"20061130 Secunia Research: MailEnable IMAP Service Two Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/453118/100/100/threaded"},{"name":"mailenable-meimaps-bo(30614)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30614"},{"name":"http://secunia.com/secunia_research/2006-71/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-71/advisory/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6291","datePublished":"2006-12-05T11:00:00.000Z","dateReserved":"2006-12-05T00:00:00.000Z","dateUpdated":"2024-08-07T20:19:35.214Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-05 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:N/A:C","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"1.1","versionEndIncluding":"1.40","matchCriteriaId":"A212F6FA-133C-4B98-A666-95C4B534F29E"},{"vulnerable":true,"criteria":"cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*","versionStartIncluding":"1.6","versionEndIncluding":"1.83","matchCriteriaId":"9BB0B6A1-661A-424E-B474-E968CBABCAB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:mailenable:mailenable:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"2.0","versionEndIncluding":"2.33","matchCriteriaId":"1D809C28-BCE0-437A-93D6-872FF0E1598C"},{"vulnerable":true,"criteria":"cpe:2.3:a:mailenable:mailenable:*:*:*:*:professional:*:*:*","versionStartIncluding":"2.0","versionEndIncluding":"2.33","matchCriteriaId":"01873EE6-BE89-46B0-9D85-8210AF0AFAFD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6291","Ordinal":"1","Title":"CVE-2006-6291","CVE":"CVE-2006-6291","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6291","Ordinal":"1","NoteData":"Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 through 1.40 and 2.0 through 2.33, allows remote authenticated users to cause a denial of service (crash) via a long argument containing * (asterisk) and ? (question mark) characters to the DELETE command, as addressed by the ME-10020 hotfix.","Type":"Description","Title":"CVE-2006-6291"},{"CveYear":"2006","CveId":"6291","Ordinal":"2","NoteData":"2006-12-05","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6291","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}