Vulnerability index

Browse CVEs

51 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Webclient HIGH 7.5
CVE-2010-5334

IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the o…

Fix: 10.2.1+
Fix from $1,950 2019-10-11
Mail Server HIGH 7.5
CVE-2019-12593EPSS 41%

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory tr…

Fix: after 10.4.4
Fix from $1,950 2019-06-03
Mail Server MEDIUM 6.1
CVE-2018-16324

In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.

Fix: after 12.0.3.1
Fix from $1,600 2018-09-01
Mail Server MEDIUM 6.1
CVE-2018-7475

Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script…

No fix yet
Fix from $1,600 2018-06-30
Mail Server HIGH 7.5
CVE-2015-1503EPSS 58%

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot)…

Fix: 11.2.0+
Fix from $1,950 2018-05-08
Server MEDIUM 6.1
CVE-2017-7855

In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.

Mitigation only
Fix from $1,600 2017-08-31
Mail Server MEDIUM 6.4
CVE-2011-3579

server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP re…

Fix: after 10.3.2
Fix from $1,600 2011-09-30
Mail Server MEDIUM 5.0
CVE-2011-3580

IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server …

Fix: after 10.3.2
Fix from $1,600 2011-09-30
Email Server MEDIUM 6.5
CVE-2009-1468

Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server…

Fix: after 9.3.0
Fix from $1,600 2009-05-05
Merak Mail Server HIGH 7.5
CVE-2009-1516

Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependen…

No fix yet
Fix from $1,950 2009-05-04
Web Mail MEDIUM 5.0
CVE-2005-3132

MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a di…

Mitigation only
Fix from $1,600 2005-10-04
Web Mail MEDIUM 5.0
CVE-2005-3133EPSS 6%

Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote at…

No fix yet
Fix from $1,600 2005-10-04
Web Mail MEDIUM 5.0
CVE-2005-1489

Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server …

Patch available
Fix from $1,600 2005-05-11
Web Mail HIGH 7.2
CVE-2005-0322

MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, …

Mitigation only
Fix from $1,950 2005-05-02
Web Mail MEDIUM 5.0
CVE-2005-0320

Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web s…

Patch available
Fix from $1,600 2005-01-28
Web Mail HIGH 7.5
CVE-2004-1672

attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attac…

Patch available
Fix from $1,950 2004-10-12
Web Mail HIGH 7.5
CVE-2004-1673

accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text fil…

Patch available
Fix from $1,950 2004-10-12
Web Mail HIGH 7.5
CVE-2004-1674

viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary fi…

Patch available
Fix from $1,950 2004-10-12
Web Mail MEDIUM 5.0
CVE-2004-1671

Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct re…

Patch available
Fix from $1,600 2004-10-12
Web Mail HIGH 7.5
CVE-2004-1670

Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers…

Patch available
Fix from $1,950 2004-09-10
Web Mail HIGH 7.5
CVE-2002-0258

Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers wi…

Mitigation only
Fix from $1,950 2002-05-29