extremail records
7 published records for vendor extremail.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 3
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-189 Numeric Errors1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
7 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
46Plan | CVE-2007-5466Proof of concept | Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strinextremail · extremail · CWE-119 | Critical10.0 | — | 19.9% | Oct 15, 2007 |
44Plan | CVE-2007-5467Proof of concept | Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, vextremail · extremail · CWE-189 | Critical10.0 | — | 13.5% | Oct 15, 2007 |
42Plan | CVE-2007-2187Proof of concept | Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response.extremail · extremail | Critical10.0 | — | 6.8% | Apr 24, 2007 |
42Plan | CVE-2001-1078Proof of concept | Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format speciextremail · extremail | Critical10.0 | — | 5.4% | Jun 21, 2001 |
41Plan | CVE-2004-0332No exploit | Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain priextremail · extremail | Critical10.0 | — | 2.5% | Nov 23, 2004 |
41Plan | CVE-2007-2188No exploit | eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers textremail · extremail | Critical10.0 | — | 2.4% | Apr 24, 2007 |
40Plan | CVE-2006-6926No exploit | Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack.extremail · extremail | Critical10.0 | — | 1.4% | Jan 12, 2007 |
- CVE-2007-546646Plan
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strin
CriticalCVSS 10.0Proof of conceptEPSS 20%extremail · extremailOct 15, 2007
- CVE-2007-546744Plan
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, v
CriticalCVSS 10.0Proof of conceptEPSS 14%extremail · extremailOct 15, 2007
- CVE-2007-218742Plan
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response.
CriticalCVSS 10.0Proof of conceptEPSS 7%extremail · extremailApr 24, 2007
- CVE-2001-107842Plan
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format speci
CriticalCVSS 10.0Proof of conceptEPSS 5%extremail · extremailJun 21, 2001
- CVE-2004-033241Plan
Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain pri
CriticalCVSS 10.0No exploitEPSS 3%extremail · extremailNov 23, 2004
- CVE-2007-218841Plan
eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers t
CriticalCVSS 10.0No exploitEPSS 2%extremail · extremailApr 24, 2007
- CVE-2006-692640Plan
Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack.
CriticalCVSS 10.0No exploitEPSS 1%extremail · extremailJan 12, 2007