Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Mail2000 MEDIUM 5.3
CVE-2024-6741

Openfind's Mail2000 has a vulnerability that allows the HttpOnly flag to be bypassed. Unauthenticated remote attackers can exploit this vulnerability…

No fix yet
Fix from $1,600 2024-07-15
Mail2000 MEDIUM 6.1
CVE-2024-6740

Openfind's Mail2000 does not properly validate email atachments, allowing unauthenticated remote attackers to inject JavaScript code within the attac…

No fix yet
Fix from $1,600 2024-07-15
Mail2000 HIGH 8.8
CVE-2024-5400

Openfind Mail2000 does not properly filter parameters of specific CGI. Remote attackers with regular privileges can exploit this vulnerability to exe…

Mitigation only
Fix from $1,950 2024-05-27
Mail2000 HIGH 7.2
CVE-2024-5399

Openfind Mail2000 does not properly filter parameters of specific API. Remote attackers with administrative privileges can exploit this vulnerability…

Mitigation only
Fix from $1,950 2024-05-27
Mail2000 MEDIUM 5.4
CVE-2023-22902

Openfind Mail2000 file uploading function has insufficient filtering for user input. An authenticated remote attacker with general user privilege can…

Mitigation only
Fix from $1,600 2023-03-27
Mailaudit HIGH 8.8
CVE-2020-25849

MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after…

Mitigation only
Fix from $1,950 2020-11-01
Mail2000 HIGH 7.2
CVE-2020-12776

Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the adminis…

Mitigation only
Fix from $1,950 2020-09-01
Mailaudit CRITICAL 9.8
CVE-2020-12782

Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be trigg…

Mitigation only
Fix from $2,300 2020-06-23
Mail2000 MEDIUM 6.1
CVE-2019-9763

An issue was discovered in Openfind Mail2000 6.0 and 7.0 Webmail. XSS can occur via an '<object data="data:text/html' substring in an e-mail message …

No fix yet
Fix from $1,600 2019-06-19