Vulnerability index

Browse CVEs

83 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2022-42136 Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission … Mailenable 8.66 / 9.85+ Fix from $1,9502023-01-13 HIGH 8.8 CVE-2019-12926 MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas. As a result, it was possible to perform a num… Mailenable 6.90 / 7.62+ Fix from $1,9502019-07-08 HIGH 8.1 CVE-2019-12925 MailEnable Enterprise Premium 10.23 was vulnerable to multiple directory traversal issues, with which authenticated users could add, remove, or poten… Mailenable 6.90 / 7.62+ Fix from $1,9502019-07-08 MEDIUM 6.1 CVE-2019-12927 MailEnable Enterprise Premium 10.23 was vulnerable to stored and reflected cross-site scripting (XSS) attacks. Because the session cookie did not use… Mailenable 6.90 / 7.62+ Fix from $1,6002019-07-08 CRITICAL 9.8 CVE-2019-12924 MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticated user.… Mailenable 6.90 / 7.62+ Fix from $2,3002019-07-08 MEDIUM 6.5 CVE-2019-12923 In MailEnable Enterprise Premium 10.23, the potential cross-site request forgery (CSRF) protection mechanism was not implemented correctly and it was… Mailenable 6.90 / 7.62+ Fix from $1,6002019-07-08 CRITICAL 10.0 CVE-2015-9280 MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter. Mailenable 8.60+ Fix from $2,3002019-01-16 CRITICAL 9.8 CVE-2015-9278 MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a pa… Mailenable 8.60+ Fix from $2,3002019-01-16 CRITICAL 9.1 CVE-2015-9277 MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.… Mailenable 8.60+ Fix from $2,3002019-01-16 MEDIUM 6.1 CVE-2015-9279 MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message. Mailenable 8.60+ Fix from $1,6002019-01-16 MEDIUM 5.0 CVE-2010-2580 The SMTP service (MESMTPC.exe) in MailEnable 3.x and 4.25 does not properly perform a length check, which allows remote attackers to cause a denial o… Mailenable after 4.25 Fix from $1,6002010-09-15 MEDIUM 5.0 CVE-2008-3449 MailEnable Professional 3.5.2 and Enterprise 3.52 allow remote attackers to cause a denial of service (crash) via multiple IMAP connection requests t… Mailenable Patch available Fix from $1,6002008-08-04 HIGH 9.0 CVE-2008-1276EPSS 7% Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow remote a… Mailenable Enterprise after 3.13 Fix from $1,9502008-03-10 HIGH 9.0 CVE-2008-1277EPSS 8% The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a denial o… Mailenable Enterprise after 3.13 Fix from $1,9502008-03-10 HIGH 7.8 CVE-2008-1275 Multiple unspecified vulnerabilities in the SMTP service in MailEnable Standard Edition 1.x, Professional Edition 3.x and earlier, and Enterprise Edi… Mailenable Enterprise after 3.0 Fix from $1,9502008-03-10 HIGH 9.0 CVE-2007-1301EPSS 12% Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticated users… Mailenable Enterprise No fix yet Fix from $1,9502007-03-07 MEDIUM 5.1 CVE-2007-0652 Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and… Mailenable Professional Patch available Fix from $1,6002007-02-15 HIGH 7.8 CVE-2007-0955EPSS 5% The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (applic… Mailenable after 2.35 Fix from $1,9502007-02-15 HIGH 10.0 CVE-2006-6997 Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edi… Mailenable Enterprise No fix yet Fix from $1,9502007-02-12 HIGH 10.0 CVE-2006-6605EPSS 6% Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprise 1.41,… Mailenable Enterprise after 2.35 Fix from $1,9502006-12-19 MEDIUM 5.0 CVE-2006-6484 The IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.34, Professional Edition 1.6 through 1.83, and Enterprise Edition 1… Mailenable Enterprise Patch available Fix from $1,6002006-12-12 HIGH 10.0 CVE-2006-6423EPSS 69% Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.6 through… Mailenable Enterprise Patch available Fix from $1,9502006-12-12 MEDIUM 6.8 CVE-2006-6291 Stack overflow in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.83 and 2.0 through 2.33, and MailEnable Enterprise 1.1 throu… Mailenable after 2.33 Fix from $1,6002006-12-05 MEDIUM 6.5 CVE-2006-6290 Multiple stack-based buffer overflows in the IMAP module (MEIMAPS.EXE) in MailEnable Professional 1.6 through 1.82 and 2.0 through 2.33, and MailEnab… Mailenable Enterprise Patch available Fix from $1,6002006-12-05 HIGH 7.5 CVE-2006-6239 webadmin in MailEnable NetWebAdmin Professional 2.32 and Enterprise 2.32 allows remote attackers to authenticate using an empty password. Netwebadmin Enterprise Patch available Fix from $1,9502006-12-03 HIGH 9.3 CVE-2006-5176EPSS 5% Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code via "the s… Mailenable Enterprise Patch available Fix from $1,9502006-10-10 HIGH 9.3 CVE-2006-5177EPSS 7% The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vecto… Mailenable Enterprise Patch available Fix from $1,9502006-10-10 MEDIUM 5.0 CVE-2006-4616 SMTP service in MailEnable Standard, Professional, and Enterprise before ME-10014 (20060904) allows remote attackers to cause a denial of service via… Mailenable Enterprise Patch available Fix from $1,6002006-09-07 MEDIUM 5.0 CVE-2006-3277EPSS 6% The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, all… Mailenable Enterprise after 1.21 Fix from $1,6002006-06-28 HIGH 10.0 CVE-2006-1792 Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition bef… Mailenable Enterprise Mitigation only Fix from $1,9502006-04-15