Skip to content
Noroxi

inter7 records

18 published records for vendor inter7.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
44.4%
Median publish → KEV
No record has entered KEV

Records by year

    Bar: total · dark part: CISA KEV.

    Recurring classes

    The weakness classes this vendor ships most often: where to look.

    CWE

    All records

    18 records
    • Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or passwor

      CriticalCVSS 10.0Proof of conceptEPSS 13%

      inter7 · vpopmailJan 21, 2000

    • CVE-2004-0777
      33Monitor

      Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBU

      HighCVSS 7.5Proof of conceptEPSS 11%

      inter7 · courier-imapOct 20, 2004

    • CVE-2006-1141
      31Monitor

      Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environme

      HighCVSS 7.5No exploitEPSS 5%

      inter7 · qmailadminMar 10, 2006

    • CVE-2004-0224
      31Monitor

      Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.

      HighCVSS 7.5No exploitEPSS 3%

      double precision incorporated · courier mtaApr 15, 2004

    • CVE-2004-2239
      31Monitor

      Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.

      HighCVSS 7.5No exploitEPSS 3%

      inter7 · vpopmail \(vchkpw\)Dec 31, 2004

    • CVE-2007-0558
      31Monitor

      PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP c

      HighCVSS 7.5Proof of conceptEPSS 2%

      inter7 · vhostadminJan 30, 2007

    • CVE-2005-1308
      31Monitor

      SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desire

      HighCVSS 7.5Proof of conceptEPSS 2%

      inter7 · sqwebmailApr 15, 2005

    • CVE-2006-2346
      31Monitor

      vpopmail 5.4.14 and 5.4.15, with cleartext passwords enabled, allows remote attackers to authenticate to an account that does not have a cle

      HighCVSS 7.5No exploitEPSS 2%

      inter7 · vpopmail \(vchkpw\)May 12, 2006

    • CVE-2003-0040
      30Monitor

      SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the u

      HighCVSS 7.5No exploitEPSS 1%

      double precision incorporated · courier mtaFeb 19, 2003

    • CVE-2004-0591
      28Monitor

      Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote at

      MediumCVSS 6.8Proof of conceptEPSS 5%

      inter7 · sqwebmailAug 6, 2004

    • CVE-2000-0583
      20Monitor

      vchkpw program in vpopmail before version 4.8 does not properly cleanse an untrusted format string used in a call to syslog, which allows re

      MediumCVSS 5.0No exploitEPSS 2%

      inter7 · vpopmail vchkpwJun 30, 2000

    • CVE-2004-2313
      20Monitor

      Inter7 SqWebMail 3.4.1 through 3.6.1 generates different error messages for incorrect passwords versus correct passwords on non-mail-enabled

      MediumCVSS 5.0No exploitEPSS 1%

      inter7 · sqwebmailDec 31, 2004

    • CVE-2004-2238
      20Monitor

      Format string vulnerability in vsybase.c in vpopmail 5.4.2 and earlier has unknown impact and attack vectors.

      MediumCVSS 5.0No exploitEPSS 1%

      inter7 · vpopmail \(vchkpw\)Dec 31, 2004

    • CVE-2005-2769
      18Monitor

      Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web scri

      MediumCVSS 4.3Proof of conceptEPSS 3%

      inter7 · sqwebmailSep 2, 2005

    • CVE-2005-2820
      18Monitor

      Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via an e-mail mes

      MediumCVSS 4.3No exploitEPSS 2%

      inter7 · sqwebmailSep 7, 2005

    • CVE-2005-2724
      18Monitor

      Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 allows remote attackers to inject arbitrary web script or HTML via a file attach

      MediumCVSS 4.3No exploitEPSS 2%

      inter7 · sqwebmailAug 30, 2005

    • CVE-2002-1414
      18Monitor

      Buffer overflow in qmailadmin allows local users to gain privileges via a long QMAILADMIN_TEMPLATEDIR environment variable.

      MediumCVSS 4.6Proof of conceptEPSS 1%

      inter7 · qmailadminApr 11, 2003

    • CVE-2001-0990
      18Monitor

      Inter7 vpopmail 4.10.35 and earlier, when using the MySQL module, compiles authentication information in cleartext into the libvpopmail.a li

      MediumCVSS 4.6No exploitEPSS 0%

      inter7 · vpopmailSep 4, 2001