hmailserver records
5 published records for vendor hmailserver.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-321 Use of Hard-coded Cryptographic Key2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
23Monitor | CVE-2013-5571No exploit | HMailServer 5.3.x and prior: Memory Corruption which could cause DOShmailserver · hmailserver · CWE-119 | Medium5.9 | — | 0.9% | Jan 7, 2020 |
20Monitor | CVE-2025-52372No exploit | An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtehmailserver · hmailserver · CWE-200 | Medium5.1 | — | 0.2% | Jul 21, 2025 |
18Monitor | CVE-2008-3676Proof of concept | Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource ehmailserver · hmailserver · CWE-20 | Medium4.3 | — | 2.8% | Aug 14, 2008 |
18Monitor | CVE-2025-52373No exploit | Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in databasehmailserver · hmailserver · CWE-321 | Medium4.6 | — | 0.3% | Jul 21, 2025 |
18Monitor | CVE-2025-52374No exploit | Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other serverhmailserver · hmailserver · CWE-321 | Medium4.6 | — | 0.2% | Jul 21, 2025 |
- CVE-2013-557123Monitor
HMailServer 5.3.x and prior: Memory Corruption which could cause DOS
MediumCVSS 5.9No exploitEPSS 1%hmailserver · hmailserverJan 7, 2020
- CVE-2025-5237220Monitor
An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExte
MediumCVSS 5.1No exploitEPSS 0%hmailserver · hmailserverJul 21, 2025
- CVE-2008-367618Monitor
Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource e
MediumCVSS 4.3Proof of conceptEPSS 3%hmailserver · hmailserverAug 14, 2008
- CVE-2025-5237318Monitor
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database
MediumCVSS 4.6No exploitEPSS 0%hmailserver · hmailserverJul 21, 2025
- CVE-2025-5237418Monitor
Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other server
MediumCVSS 4.6No exploitEPSS 0%hmailserver · hmailserverJul 21, 2025