Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2006-2923

18
FAUCET Score

CVE-2006-2923 describes a critical buffer overflow vulnerability within the iax_net_read function of the iaxclient open-source library, impacting numerous products including LoudHush, IDE FISK, Kiax, and others utilizing IAX 2 (IAX2) communication. This flaw allows remote attackers to execute arbitrary code by sending specially crafted IAX2 packets with truncated full or mini-frames, which are improperly processed despite length checks, leading to negative length values and subsequent buffer overflows. The vulnerability carries a CVSS score of 6.4, indicating a medium severity with a network attack vector, low attack complexity, and potential for partial confidentiality and integrity impact. While the EPSS score suggests a low likelihood of exploitation, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this decade-old vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
1.3.6CPE matchmatch criteria
cpe:2.3:a:loudhush:loudhush:1.3.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.4MEDIUM

AV:N/AC:L/Au:N/C:P/I:P/A:N

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
LOW
Authentication
NONE
Exploitability Score
10.0
Impact Score
4.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
4.38%
Probability of exploitation in next 30 days
EPSS Percentile
90.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0438 is in the 87th percentile among its peer group of 23,701 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

iaxclient.sourceforge.net / iaxcomm
secunia.com / advisories/20466
PatchVendor Advisory
secunia.com / advisories/20560
Vendor Advisory
secunia.com / advisories/20567
Vendor Advisory
secunia.com / advisories/20623
Vendor Advisory
secunia.com / advisories/20900
Vendor Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/27047
sourceforge.net / project/shownotes.php
coresecurity.com / common/showdoc.php
gentoo.org / security/en/glsa/glsa-200606-30.xml
loudhush.ro / changelog.txt
securityfocus.com / archive/1/436638/100/0/threaded
securityfocus.com / bid/18307
Patch
vupen.com / english/advisories/2006/2180
Vendor Advisory
vupen.com / english/advisories/2006/2284
Vendor Advisory
vupen.com / english/advisories/2006/2285
Vendor Advisory
vupen.com / english/advisories/2006/2286
Vendor Advisory