Vulnerability index

Browse CVEs

51 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2010-5334 IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the o… Webclient 10.2.1+ Fix from $1,9502019-10-11 HIGH 7.5 CVE-2019-12593EPSS 41% IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory tr… Mail Server after 10.4.4 Fix from $1,9502019-06-03 MEDIUM 6.1 CVE-2018-16324 In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field. Mail Server after 12.0.3.1 Fix from $1,6002018-09-01 MEDIUM 6.1 CVE-2018-7475 Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script… Mail Server No fix yet Fix from $1,6002018-06-30 HIGH 7.5 CVE-2015-1503EPSS 58% Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot)… Mail Server 11.2.0+ Fix from $1,9502018-05-08 MEDIUM 6.1 CVE-2017-7855 In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter. Server Mitigation only Fix from $1,6002017-08-31 MEDIUM 6.4 CVE-2011-3579 server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly send HTTP re… Mail Server after 10.3.2 Fix from $1,6002011-09-30 MEDIUM 5.0 CVE-2011-3580 IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to obtain configuration information via a direct request to the /server … Mail Server after 10.3.2 Fix from $1,6002011-09-30 MEDIUM 6.5 CVE-2009-1468 Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMail Server… Email Server after 9.3.0 Fix from $1,6002009-05-05 HIGH 7.5 CVE-2009-1516 Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context-dependen… Merak Mail Server No fix yet Fix from $1,9502009-05-04 MEDIUM 5.0 CVE-2005-3132 MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a di… Web Mail Mitigation only Fix from $1,6002005-10-04 MEDIUM 5.0 CVE-2005-3133EPSS 6% Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote at… Web Mail No fix yet Fix from $1,6002005-10-04 MEDIUM 5.0 CVE-2005-1489 Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server … Web Mail Patch available Fix from $1,6002005-05-11 HIGH 7.2 CVE-2005-0322 MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, … Web Mail Mitigation only Fix from $1,9502005-05-02 MEDIUM 5.0 CVE-2005-0320 Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web s… Web Mail Patch available Fix from $1,6002005-01-28 HIGH 7.5 CVE-2004-1672 attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attac… Web Mail Patch available Fix from $1,9502004-10-12 HIGH 7.5 CVE-2004-1673 accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create text fil… Web Mail Patch available Fix from $1,9502004-10-12 HIGH 7.5 CVE-2004-1674 viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary fi… Web Mail Patch available Fix from $1,9502004-10-12 MEDIUM 5.0 CVE-2004-1671 Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to gain sensitive information via a direct re… Web Mail Patch available Fix from $1,6002004-10-12 HIGH 7.5 CVE-2004-1670 Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers… Web Mail Patch available Fix from $1,9502004-09-10 HIGH 7.5 CVE-2002-0258 Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers wi… Web Mail Mitigation only Fix from $1,9502002-05-29