Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mailenable vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2019-12927
MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use the HttpOnly flag, it was possible to hijack the session cookie by exploiting this vulnerability.
Mailenable Mailenable
5
CVSSv2
CVE-2008-3449
MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote malicious users to cause a denial of service (crash) via multiple IMAP connection requests to the same folder.
Mailenable Mailenable 3.52
4.3
CVSSv2
CVE-2012-2588
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote malicious users to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.
Mailenable Mailenable 6.5
1 EDB exploit
5
CVSSv2
CVE-2004-2726
HTTPMail service in MailEnable Professional 1.18 does not properly handle arguments to the Authorization header, which allows remote malicious users to cause a denial of service (null dereference and application crash). NOTE: This is a different vulnerability than CVE-2005-1348.
Mailenable Mailenable 1.18
7.2
CVSSv2
CVE-2005-2278
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.
Mailenable Mailenable Professional 1.54
1 EDB exploit
7.5
CVSSv2
CVE-2005-4457
MailEnable Enterprise 1.1 before patch ME-10009 allows remote malicious users to cause a denial of service (crash) and possibly execute arbitrary code via several "..." (triple dot) sequences in a UID FETCH command.
Mailenable Mailenable Enterprise 1.1
5
CVSSv2
CVE-2005-0804
Format string vulnerability in MailEnable 1.8 allows remote malicious users to cause a denial of service (application crash) via format string specifiers in the mailto field.
Mailenable Mailenable Standard 1.8
1 EDB exploit
7.5
CVSSv2
CVE-2006-6239
webadmin in MailEnable NetWebAdmin Professional 2.32 and Enterprise 2.32 allows remote malicious users to authenticate using an empty password.
Mailenable Netwebadmin Enterprise 2.32
Mailenable Netwebadmin Professional 2.32
10
CVSSv2
CVE-2005-1015
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote malicious users to execute arbitrary code via a long LOGIN command.
Mailenable Imapd
5
CVSSv2
CVE-2005-3691
Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and previous versions and Enterprise 1.1 and previous versions allows remote malicious users to create or rename arbitrary mail directories via the mailbox name argument of the (1) ...
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2021-35000
CVE-2024-4439
unauthorized
CVE-2024-0042
CVE-2024-31848
CVE-2023-40694
cache poisoning
CVE-2024-23707
firmware
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6