Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
merak mail server vulnerabilities and exploits
(subscribe to this query)
6.5
CVSSv2
CVE-2005-4558
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter to mail/settings.html before it is stored in a database, which can allow remote authenticated users ...
Merak Mail Server 8.3.0r
Deerfield Visnetic Mail Server 8.3.0 Build1
Icewarp Web Mail 5.5.1
2 EDB exploits
4
CVSSv2
CVE-2006-0818
Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer prior to 8.5.0.5 allows remote authenticated users to include arbitrary files via a modified language parameter and a full Wi...
Icewarp Web Mail 5.6.0
Merak Mail Server 8.3.8r
Deerfield Visnetic Mail Server 8.3.5
7.5
CVSSv2
CVE-2009-1516
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependent malicious users to execute arbitrary code via a large value in the second argument to the Base64FileEncode method, as possibly de...
Icewarp Merak Mail Server 9.4.1
1 EDB exploit
4.3
CVSSv2
CVE-2008-5734
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote malicious users to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
Icewarp Merak Mail Server 9.3.2
7.5
CVSSv2
CVE-2004-1670
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote malicious users to (1) create arbitrary directories via a .. (dot dot) in the user parameter to viewaction.html or (2) rename arbitrary file...
Icewarp Web Mail 5.2.8
Merak Mail Server 7.4.5
Icewarp Web Mail 3.3.2
Icewarp Web Mail 5.2.7
7.5
CVSSv2
CVE-2004-1674
viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote malicious users to (1) delete arbitrary files via the originalfolder parameter or (2) move arbitrary files via the messageid parameter.
Icewarp Web Mail 5.2.8
Merak Mail Server 7.4.5
Icewarp Web Mail 3.3.2
Icewarp Web Mail 5.2.7
4.3
CVSSv2
CVE-2004-1669
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote malicious users to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter...
Merak Mail Server 7.4.5
Icewarp Web Mail 3.3.2
Icewarp Web Mail 5.2.7
Icewarp Web Mail 5.2.8
7.5
CVSSv2
CVE-2004-1673
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote malicious users to create text files with arbitrary content via the accountid parameter.
Icewarp Web Mail 5.2.7
Icewarp Web Mail 5.2.8
Icewarp Web Mail 3.3.2
4.3
CVSSv2
CVE-2009-1469
CRLF injection vulnerability in the Forgot Password implementation in server/webmail.php in IceWarp eMail Server and WebMail Server prior to 9.4.2 makes it easier for remote malicious users to trick a user into disclosing credentials via CRLF sequences preceding a Reply-To header...
Icewarp Webmail Server 2.10.170
Icewarp Webmail Server 2.10.200
Icewarp Webmail Server 2.10.290
Icewarp Webmail Server 2.10.320
Icewarp Webmail Server 3.00.120
Icewarp Webmail Server 3.00.130
Icewarp Webmail Server 4.2.1
Icewarp Webmail Server 4.2.2
Icewarp Webmail Server 5.4.1
Icewarp Webmail Server 5.4.2
Icewarp Webmail Server 5.5.7
Icewarp Webmail Server 5.7.3
Icewarp Webmail Server 6.0.2
Icewarp Webmail Server 6.0.3
Icewarp Webmail Server 6.0.5
Icewarp Webmail Server 7.1.6
Icewarp Webmail Server 7.2.0
Icewarp Webmail Server 8.0.1
Icewarp Webmail Server 8.0.3
Icewarp Webmail Server 8.9.1
Icewarp Webmail Server 9.0.0
Icewarp Webmail Server 9.1.0
1 EDB exploit
5
CVSSv2
CVE-2004-1671
Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote malicious users to gain sensitive information via a direct request to (1) accountsettings_add.html or (2) topmenu.html.
Icewarp Web Mail 5.2.7
Icewarp Web Mail 5.2.8
Icewarp Web Mail 3.3.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-52710
arbitrary
CVE-2024-5272
CVE-2024-2961
brute force
remote
CVE-2024-32944
CVE-2024-36241
CVE-2024-5274
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »