isode records
6 published records for vendor isode.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-284 Improper Access Control1
- CWE-798 Use of Hard-coded Credentials1
The weakness classes this vendor ships most often: where to look.
CWEAll records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2014-2742No exploit | Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a deisode · m-link · CWE-264 | High7.8 | — | 1.8% | Apr 10, 2014 |
32Monitor | CVE-2022-47634No exploit | M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archiveisode · m-link · CWE-284 | High8.1 | — | 0.5% | Jan 1, 2023 |
31Monitor | CVE-2006-0710Proof of concept | Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP reisode · m-vault server · CWE-119 | High7.5 | — | 4.5% | Feb 15, 2006 |
30Monitor | CVE-2022-47581No exploit | Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.isode · m-vault | High7.5 | — | 0.6% | Dec 21, 2022 |
30Monitor | CVE-2022-32389No exploit | Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor.isode · swift · CWE-798 | High7.5 | — | 0.6% | Jul 14, 2022 |
23Monitor | CVE-2012-4669No exploit | M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which aisode · m-link · CWE-20 | Medium5.8 | — | 0.9% | Aug 25, 2012 |
- CVE-2014-274232Monitor
Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a de
HighCVSS 7.8No exploitEPSS 2%isode · m-linkApr 10, 2014
- CVE-2022-4763432Monitor
M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive
HighCVSS 8.1No exploitEPSS 0%isode · m-linkJan 1, 2023
- CVE-2006-071031Monitor
Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP re
HighCVSS 7.5Proof of conceptEPSS 5%isode · m-vault serverFeb 15, 2006
- CVE-2022-4758130Monitor
Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request.
HighCVSS 7.5No exploitEPSS 1%isode · m-vaultDec 21, 2022
- CVE-2022-3238930Monitor
Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor.
HighCVSS 7.5No exploitEPSS 1%isode · swiftJul 14, 2022
- CVE-2012-466923Monitor
M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which a
MediumCVSS 5.8No exploitEPSS 1%isode · m-linkAug 25, 2012