kerio records
44 published records for vendor kerio.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 2.3%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-16 Configuration1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
44 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
51Plan | CVE-2003-0220Weaponized | Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to ekerio · personal firewall 2 | High7.5 | — | 69.1% | May 12, 2003 |
41Plan | CVE-2007-3993No exploit | Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.kerio · kerio mailserver | Critical10.0 | — | 1.8% | Jul 25, 2007 |
41Plan | CVE-2004-2441No exploit | Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential seckerio · kerio mailserver | Critical10.0 | — | 1.7% | Dec 31, 2004 |
40Plan | CVE-2008-0860No exploit | Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors relatekerio · avg plugin | Critical10.0 | — | 1.5% | Feb 20, 2008 |
33Monitor | CVE-2003-0487Proof of concept | Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitkerio · kerio mailserver | High7.5 | — | 11.4% | Aug 7, 2003 |
32Monitor | CVE-2006-1158No exploit | Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN commkerio · kerio mailserver | High7.8 | — | 2.1% | Mar 12, 2006 |
32Monitor | CVE-2005-4425No exploit | Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain Rkerio · winroute firewall | High7.8 | — | 1.8% | Dec 20, 2005 |
31Monitor | CVE-2008-0858No exploit | Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code vikerio · kerio mailserver · CWE-94 | High7.5 | — | 4.0% | Feb 20, 2008 |
31Monitor | CVE-2003-0219No exploit | Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid skerio · personal firewall 2 | High7.5 | — | 3.8% | May 12, 2003 |
31Monitor | CVE-2005-1062No exploit | The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allokerio · kerio mailserver | High7.5 | — | 2.6% | May 2, 2005 |
31Monitor | CVE-2003-1491No exploit | Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bkerio · personal firewall · CWE-16 | High7.5 | — | 2.4% | Dec 31, 2003 |
31Monitor | CVE-2005-4157No exploit | Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account thkerio · winroute firewall | High7.5 | — | 1.7% | Dec 10, 2005 |
28Monitor | CVE-2002-1434Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML sckerio · kerio mailserver | Medium6.8 | — | 4.3% | Apr 11, 2003 |
28Monitor | CVE-2011-1506No exploit | The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-kerio · connect · CWE-20 | Medium6.8 | — | 2.5% | Mar 22, 2011 |
28Monitor | CVE-2004-2329No exploit | Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall kerio · personal firewall | High7.2 | — | 0.6% | Dec 31, 2004 |
27Monitor | CVE-2014-3857Proof of concept | Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote akerio · control · CWE-89 | Medium6.5 | — | 2.2% | Jul 3, 2014 |
26Monitor | CVE-2004-2483No exploit | Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison thekerio · winroute firewall | Medium6.4 | — | 1.7% | Dec 31, 2004 |
25Monitor | CVE-2006-2203No exploit | Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attkerio · kerio mailserver | Medium6.4 | — | 1.2% | May 5, 2006 |
24Monitor | CVE-2006-6131Proof of concept | Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier alkerio · webstar | Medium6.2 | — | 0.9% | Nov 27, 2006 |
22Monitor | CVE-2003-0488Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) kerio · kerio mailserver | Medium5.1 | — | 6.8% | Aug 7, 2003 |
21Monitor | CVE-2004-1109Proof of concept | The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and kerio · personal firewall | Medium5.0 | — | 3.2% | Jan 10, 2005 |
21Monitor | CVE-2006-2267No exploit | Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "emkerio · winroute firewall | Medium5.0 | — | 3.2% | May 9, 2006 |
21Monitor | CVE-2006-0335No exploit | Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service viakerio · winroute firewall | Medium5.0 | — | 2.7% | Jan 20, 2006 |
21Monitor | CVE-2006-5420No exploit | Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.kerio · winroute firewall | Medium5.0 | — | 2.6% | Oct 20, 2006 |
21Monitor | CVE-2006-0336No exploit | Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors inkerio · winroute firewall | Medium5.0 | — | 2.0% | Jan 20, 2006 |
- CVE-2003-022051Plan
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to e
HighCVSS 7.5WeaponizedEPSS 69%kerio · personal firewall 2May 12, 2003
- CVE-2007-399341Plan
Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.
CriticalCVSS 10.0No exploitEPSS 2%kerio · kerio mailserverJul 25, 2007
- CVE-2004-244141Plan
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential sec
CriticalCVSS 10.0No exploitEPSS 2%kerio · kerio mailserverDec 31, 2004
- CVE-2008-086040Plan
Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors relate
CriticalCVSS 10.0No exploitEPSS 2%kerio · avg pluginFeb 20, 2008
- CVE-2003-048733Monitor
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbit
HighCVSS 7.5Proof of conceptEPSS 11%kerio · kerio mailserverAug 7, 2003
- CVE-2006-115832Monitor
Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN comm
HighCVSS 7.8No exploitEPSS 2%kerio · kerio mailserverMar 12, 2006
- CVE-2005-442532Monitor
Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain R
HighCVSS 7.8No exploitEPSS 2%kerio · winroute firewallDec 20, 2005
- CVE-2008-085831Monitor
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code vi
HighCVSS 7.5No exploitEPSS 4%kerio · kerio mailserverFeb 20, 2008
- CVE-2003-021931Monitor
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid s
HighCVSS 7.5No exploitEPSS 4%kerio · personal firewall 2May 12, 2003
- CVE-2005-106231Monitor
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allo
HighCVSS 7.5No exploitEPSS 3%kerio · kerio mailserverMay 2, 2005
- CVE-2003-149131Monitor
Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to b
HighCVSS 7.5No exploitEPSS 2%kerio · personal firewallDec 31, 2003
- CVE-2005-415731Monitor
Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account th
HighCVSS 7.5No exploitEPSS 2%kerio · winroute firewallDec 10, 2005
- CVE-2002-143428Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML sc
MediumCVSS 6.8Proof of conceptEPSS 4%kerio · kerio mailserverApr 11, 2003
- CVE-2011-150628Monitor
The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-
MediumCVSS 6.8No exploitEPSS 2%kerio · connectMar 22, 2011
- CVE-2004-232928Monitor
Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall
HighCVSS 7.2No exploitEPSS 1%kerio · personal firewallDec 31, 2004
- CVE-2014-385727Monitor
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote a
MediumCVSS 6.5Proof of conceptEPSS 2%kerio · controlJul 3, 2014
- CVE-2004-248326Monitor
Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the
MediumCVSS 6.4No exploitEPSS 2%kerio · winroute firewallDec 31, 2004
- CVE-2006-220325Monitor
Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of att
MediumCVSS 6.4No exploitEPSS 1%kerio · kerio mailserverMay 5, 2006
- CVE-2006-613124Monitor
Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier al
MediumCVSS 6.2Proof of conceptEPSS 1%kerio · webstarNov 27, 2006
- CVE-2003-048822Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1)
MediumCVSS 5.1Proof of conceptEPSS 7%kerio · kerio mailserverAug 7, 2003
- CVE-2004-110921Monitor
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and
MediumCVSS 5.0Proof of conceptEPSS 3%kerio · personal firewallJan 10, 2005
- CVE-2006-226721Monitor
Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "em
MediumCVSS 5.0No exploitEPSS 3%kerio · winroute firewallMay 9, 2006
- CVE-2006-033521Monitor
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via
MediumCVSS 5.0No exploitEPSS 3%kerio · winroute firewallJan 20, 2006
- CVE-2006-542021Monitor
Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.
MediumCVSS 5.0No exploitEPSS 3%kerio · winroute firewallOct 20, 2006
- CVE-2006-033621Monitor
Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors in
MediumCVSS 5.0No exploitEPSS 2%kerio · winroute firewallJan 20, 2006