Vulnerability index

Browse CVEs

83 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mailenable HIGH 8.8
CVE-2022-42136

Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission …

Fix: 8.66 / 9.85+
Fix from $1,950 2023-01-13
Mailenable HIGH 8.8
CVE-2019-12926

MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a num…

Fix: 6.90 / 7.62+
Fix from $1,950 2019-07-08
Mailenable HIGH 8.1
CVE-2019-12925

MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or poten…

Fix: 6.90 / 7.62+
Fix from $1,950 2019-07-08
Mailenable MEDIUM 6.1
CVE-2019-12927

MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use…

Fix: 6.90 / 7.62+
Fix from $1,600 2019-07-08
Mailenable CRITICAL 9.8
CVE-2019-12924

MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.…

Fix: 6.90 / 7.62+
Fix from $2,300 2019-07-08
Mailenable MEDIUM 6.5
CVE-2019-12923

In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was…

Fix: 6.90 / 7.62+
Fix from $1,600 2019-07-08
Mailenable CRITICAL 10.0
CVE-2015-9280

MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.

Fix: 8.60+
Fix from $2,300 2019-01-16
Mailenable CRITICAL 9.8
CVE-2015-9278

MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a pa…

Fix: 8.60+
Fix from $2,300 2019-01-16
Mailenable CRITICAL 9.1
CVE-2015-9277

MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.…

Fix: 8.60+
Fix from $2,300 2019-01-16
Mailenable MEDIUM 6.1
CVE-2015-9279

MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.

Fix: 8.60+
Fix from $1,600 2019-01-16
Mailenable MEDIUM 5.0
CVE-2010-2580

The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial o…

Fix: after 4.25
Fix from $1,600 2010-09-15
Mailenable MEDIUM 5.0
CVE-2008-3449

MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests t…

Patch available
Fix from $1,600 2008-08-04
Mailenable Enterprise HIGH 9.0
CVE-2008-1276EPSS 7%

Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote a…

Fix: after 3.13
Fix from $1,950 2008-03-10
Mailenable Enterprise HIGH 9.0
CVE-2008-1277EPSS 8%

The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial o…

Fix: after 3.13
Fix from $1,950 2008-03-10
Mailenable Enterprise HIGH 7.8
CVE-2008-1275

Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edi…

Fix: after 3.0
Fix from $1,950 2008-03-10
Mailenable Enterprise HIGH 9.0
CVE-2007-1301EPSS 12%

Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users…

No fix yet
Fix from $1,950 2007-03-07
Mailenable Professional MEDIUM 5.1
CVE-2007-0652

Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and…

Patch available
Fix from $1,600 2007-02-15
Mailenable HIGH 7.8
CVE-2007-0955EPSS 5%

The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (applic…

Fix: after 2.35
Fix from $1,950 2007-02-15
Mailenable Enterprise HIGH 10.0
CVE-2006-6997

Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi…

No fix yet
Fix from $1,950 2007-02-12
Mailenable Enterprise HIGH 10.0
CVE-2006-6605EPSS 6%

Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41,…

Fix: after 2.35
Fix from $1,950 2006-12-19
Mailenable Enterprise MEDIUM 5.0
CVE-2006-6484

The IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.34, Professional Edition 1.6 through 1.83, and Enterprise Edition 1…

Patch available
Fix from $1,600 2006-12-12
Mailenable Enterprise HIGH 10.0
CVE-2006-6423EPSS 69%

Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through…

Patch available
Fix from $1,950 2006-12-12
Mailenable MEDIUM 6.8
CVE-2006-6291

Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 throu…

Fix: after 2.33
Fix from $1,600 2006-12-05
Mailenable Enterprise MEDIUM 6.5
CVE-2006-6290

Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnab…

Patch available
Fix from $1,600 2006-12-05
Netwebadmin Enterprise HIGH 7.5
CVE-2006-6239

webadmin in MailEnable NetWebAdmin Professional 2.32 and Enterprise 2.32 allows remote attackers to authenticate using an empty password.

Patch available
Fix from $1,950 2006-12-03
Mailenable Enterprise HIGH 9.3
CVE-2006-5176EPSS 5%

Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the s…

Patch available
Fix from $1,950 2006-10-10
Mailenable Enterprise HIGH 9.3
CVE-2006-5177EPSS 7%

The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vecto…

Patch available
Fix from $1,950 2006-10-10
Mailenable Enterprise MEDIUM 5.0
CVE-2006-4616

SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via…

Patch available
Fix from $1,600 2006-09-07
Mailenable Enterprise MEDIUM 5.0
CVE-2006-3277EPSS 6%

The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, all…

Fix: after 1.21
Fix from $1,600 2006-06-28
Mailenable Enterprise HIGH 10.0
CVE-2006-1792

Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition bef…

Mitigation only
Fix from $1,950 2006-04-15