Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Control MEDIUM 6.5
CVE-2014-3857

Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authentica…

Fix: after 8.3.1
Fix from $1,600 2014-07-03
Connect MEDIUM 6.8
CVE-2011-1506

The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-mi…

Mitigation only
Fix from $1,600 2011-03-22
Avg Plugin HIGH 10.0
CVE-2008-0860

Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null…

Fix: after 6.4.2
Fix from $1,950 2008-02-21
Kerio Mailserver HIGH 7.5
CVE-2008-0858

Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspeci…

Fix: after 6.4.2
Fix from $1,950 2008-02-21
Kerio Mailserver MEDIUM 5.0
CVE-2008-0859

Unspecified vulnerability in Kerio MailServer before 6.5.0 allows remote attackers to cause a denial of service (crash) via unspecified vectors relat…

Mitigation only
Fix from $1,600 2008-02-21
Kerio Mailserver HIGH 10.0
CVE-2007-3993

Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.

Fix: after 6.4.0
Fix from $1,950 2007-07-25
Kerio Mailserver MEDIUM 5.0
CVE-2006-6554

Unspecified vulnerability in Kerio MailServer before 6.3.1 allows remote attackers to cause a denial of service (segmentation fault and service stop)…

Fix: after 6.3.0
Fix from $1,600 2006-12-14
Webstar MEDIUM 6.2
CVE-2006-6131

Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier allows loca…

Fix: after 5.4.2
Fix from $1,600 2006-11-28
Kerio Mailserver MEDIUM 5.0
CVE-2006-5812

Unspecified vulnerability in Kerio MailServer allows attackers to cause a denial of service, as demonstrated by vd_kms4.pm, a "Kerio MailServer DoS."…

No fix yet
Fix from $1,600 2006-11-08
Winroute Firewall MEDIUM 5.0
CVE-2006-5420

Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.

Fix: after 6.2.2
Fix from $1,600 2006-10-20
Personal Firewall MEDIUM 5.0
CVE-2006-5153

The (1) fwdrv.sys and (2) khips.sys drivers in Sunbelt Kerio Personal Firewall 4.3.268 and earlier do not validate arguments passed through to SSDT f…

No fix yet
Fix from $1,600 2006-10-05
Winroute Firewall MEDIUM 5.0
CVE-2006-2267

Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "email proto…

Patch available
Fix from $1,600 2006-05-09
Kerio Mailserver MEDIUM 6.4
CVE-2006-2203

Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attachment f…

Patch available
Fix from $1,600 2006-05-05
Kerio Mailserver HIGH 7.8
CVE-2006-1158

Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.

Patch available
Fix from $1,950 2006-03-12
Winroute Firewall MEDIUM 5.0
CVE-2006-0335

Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple…

Patch available
Fix from $1,600 2006-01-21
Winroute Firewall MEDIUM 5.0
CVE-2006-0336

Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "…

No fix yet
Fix from $1,600 2006-01-21
Winroute Firewall HIGH 7.8
CVE-2005-4425

Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain RTSP strea…

Patch available
Fix from $1,950 2005-12-20
Kerio Mailserver HIGH 7.5
CVE-2005-1062

The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote…

Mitigation only
Fix from $1,950 2005-05-02
Kerio Mailserver MEDIUM 5.0
CVE-2005-1063

The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote…

Patch available
Fix from $1,600 2005-04-29
Kerio Mailserver MEDIUM 5.0
CVE-2005-1138

Unknown vulnerability in WebMail in Kerio MailServer before 6.0.9 allows remote attackers to cause a denial of service (CPU consumption) via certain …

Patch available
Fix from $1,600 2005-04-18
Personal Firewall MEDIUM 5.0
CVE-2004-1109

The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and system fr…

Patch available
Fix from $1,600 2005-01-10
Kerio Mailserver HIGH 10.0
CVE-2004-2441

Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security iss…

Patch available
Fix from $1,950 2004-12-31
Personal Firewall HIGH 7.2
CVE-2004-2329

Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall Configura…

No fix yet
Fix from $1,950 2004-12-31
Winroute Firewall MEDIUM 6.4
CVE-2004-2483

Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the DNS cach…

Patch available
Fix from $1,600 2004-12-31
Personal Firewall HIGH 7.5
CVE-2003-1491

Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bypass the…

Mitigation only
Fix from $1,950 2003-12-31
Kerio Mailserver HIGH 7.5
CVE-2003-0487EPSS 11%

Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code…

Patch available
Fix from $1,950 2003-08-07
Kerio Mailserver MEDIUM 5.1
CVE-2003-0488EPSS 7%

Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_n…

Patch available
Fix from $1,600 2003-08-07
Personal Firewall 2 HIGH 7.5
CVE-2003-0219

Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid session an…

Patch available
Fix from $1,950 2003-05-12
Personal Firewall 2 HIGH 7.5
CVE-2003-0220EPSS 69%

Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute ar…

Patch available
Fix from $1,950 2003-05-12
Kerio Mailserver MEDIUM 6.8
CVE-2002-1434

Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as o…

Patch available
Fix from $1,600 2003-04-11