CVE-2006-3840
Title: Iss Proventia M Series Xpu Denial of Service (DoS)
Denial of Service (DoS)
Proof Of Concept
No public PoC currently indexed for CVE-2006-3840.
CWE Category
CWE-399
Published Date
Jul 27, 2006
Modified Date
Apr 03, 2025
Exploit Status
Not Found
Score
5.0
CVSS v2.0
Exploit Probability (EPSS)
4.12%
Vulnerability Summary
CVE-2006-3840: The SMB Mailslot parsing functionality in PAM in multiple ISS products with XPU (24.39/1.78/epj/x.x.x.1780), including Proventia A, G, M, Server, and Desktop, BlackICE PC and Server Protection 3.6, and RealSecure 7.0, allows remote attackers to cause a denial of service (infinite loop) via a crafted SMB packet that is not properly handled by the SMB_Mailslot_Heap_Overflow decode.
Impacted Vendors
Reference Links
http://secunia.com/advisories/21219
http://securitytracker.com/id?1016590
http://securitytracker.com/id?1016591
http://securitytracker.com/id?1016592
http://www.nsfocus.com/english/homepage/research/0607.htm
http://www.securityfocus.com/archive/1/441278/100/0/threaded
http://www.securityfocus.com/bid/19178
http://www.vupen.com/english/advisories/2006/2996
http://xforce.iss.net/xforce/alerts/id/230
https://exchange.xforce.ibmcloud.com/vulnerabilities/27965
https://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=3630
http://secunia.com/advisories/21219
http://securitytracker.com/id?1016590
http://securitytracker.com/id?1016591
http://securitytracker.com/id?1016592
http://www.nsfocus.com/english/homepage/research/0607.htm
http://www.securityfocus.com/archive/1/441278/100/0/threaded
http://www.securityfocus.com/bid/19178
http://www.vupen.com/english/advisories/2006/2996
http://xforce.iss.net/xforce/alerts/id/230
https://exchange.xforce.ibmcloud.com/vulnerabilities/27965
https://iss.custhelp.com/cgi-bin/iss.cfg/php/enduser/std_adp.php?p_faqid=3630
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
5.0
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:N/I:N/A:P
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2006-3840 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:N/I:N/A:P
Affected Stack
No specific products linked.