MailEnable records
90 published records for vendor mailenable.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 4 · 4.4%
- Pre-auth RCE
- 26
- With a fix record
- 2.2%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-427 Uncontrolled Search Path Element10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-399 Resource Management Errors3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
90 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2006-6423Weaponized | Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.mailenable · mailenable enterprise | Critical10.0 | — | 70.7% | Dec 11, 2006 |
55Plan | CVE-2025-44148Proof of concept | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx comailenable · mailenable · CWE-79 | Critical9.8 | — | 54.7% | Jun 3, 2025 |
53Plan | CVE-2005-2278Weaponized | Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrarmailenable · mailenable professional | High7.2 | — | 84.6% | Jul 18, 2005 |
52Plan | CVE-2005-1348Weaponized | Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute amailenable · mailenable enterprise | High7.5 | — | 72.6% | May 2, 2005 |
49Plan | CVE-2005-3155Weaponized | Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.mailenable · mailenable enterprise | High7.5 | — | 63.7% | Oct 5, 2005 |
45Plan | CVE-2005-1015No exploit | Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.mailenable · imapd | Critical10.0 | — | 16.2% | May 2, 2005 |
42Plan | CVE-2006-6605No exploit | Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprmailenable · mailenable enterprise | Critical10.0 | — | 5.9% | Dec 19, 2006 |
41Plan | CVE-2006-1792No exploit | Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edmailenable · mailenable enterprise | Critical10.0 | — | 1.9% | Apr 15, 2006 |
41Plan | CVE-2015-9280No exploit | MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.mailenable · mailenable · CWE-611 | Critical10.0 | — | 1.8% | Jan 16, 2019 |
41Plan | CVE-2006-6997No exploit | Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Entermailenable · mailenable enterprise · CWE-287 | Critical10.0 | — | 1.8% | Feb 12, 2007 |
40Plan | CVE-2007-1301Proof of concept | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticamailenable · mailenable enterprise | Critical9.0 | — | 12.2% | Mar 6, 2007 |
40Plan | CVE-2015-9278No exploit | MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB amailenable · mailenable · CWE-255 | Critical9.8 | — | 2.5% | Jan 16, 2019 |
40Plan | CVE-2005-2222No exploit | Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.mailenable · mailenable professional | Critical10.0 | — | 1.4% | Jul 12, 2005 |
39Monitor | CVE-2006-5177Proof of concept | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecifmailenable · mailenable enterprise · CWE-119 | Critical9.3 | — | 7.1% | Oct 10, 2006 |
39Monitor | CVE-2006-5176No exploit | Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code vmailenable · mailenable enterprise · CWE-119 | Critical9.3 | — | 5.4% | Oct 10, 2006 |
39Monitor | CVE-2019-12924No exploit | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticamailenable · mailenable · CWE-311 | Critical9.8 | — | 0.9% | Jul 8, 2019 |
38Monitor | CVE-2008-1277Proof of concept | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause amailenable · mailenable enterprise · CWE-20 | Critical9.0 | — | 8.3% | Mar 10, 2008 |
38Monitor | CVE-2008-1276Proof of concept | Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allowmailenable · mailenable enterprise · CWE-119 | Critical9.0 | — | 7.1% | Mar 10, 2008 |
37Monitor | CVE-2015-9277No exploit | MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../mailenable · mailenable · CWE-22 | Critical9.1 | — | 2.2% | Jan 16, 2019 |
35Monitor | CVE-2005-2223No exploit | Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a dmailenable · mailenable professional | Medium5.0 | — | 50.8% | Jul 12, 2005 |
35Monitor | CVE-2019-12926No exploit | MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.mailenable · mailenable · CWE-862 | High8.8 | — | 0.9% | Jul 8, 2019 |
35Monitor | CVE-2022-42136No exploit | Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pemailenable · mailenable · CWE-22 | High8.8 | — | 0.9% | Jan 13, 2023 |
34Monitor | CVE-2004-2501Proof of concept | Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute amailenable · mailenable enterprise | High7.5 | — | 14.1% | Dec 31, 2004 |
34Monitor | CVE-2026-44400No exploit | MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdminmailenable · mailenable · CWE-639 | High8.7 | — | 0.6% | May 8, 2026 |
34Monitor | CVE-2025-34421No exploit | MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLLmailenable · mailenable · CWE-427 | High8.5 | — | 0.2% | Dec 10, 2025 |
- CVE-2006-642361This week
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.
CriticalCVSS 10.0WeaponizedEPSS 71%mailenable · mailenable enterpriseDec 11, 2006
- CVE-2025-4414855Plan
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx co
CriticalCVSS 9.8Proof of conceptEPSS 55%mailenable · mailenableJun 3, 2025
- CVE-2005-227853Plan
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrar
HighCVSS 7.2WeaponizedEPSS 85%mailenable · mailenable professionalJul 18, 2005
- CVE-2005-134852Plan
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute a
HighCVSS 7.5WeaponizedEPSS 73%mailenable · mailenable enterpriseMay 2, 2005
- CVE-2005-315549Plan
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
HighCVSS 7.5WeaponizedEPSS 64%mailenable · mailenable enterpriseOct 5, 2005
- CVE-2005-101545Plan
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
CriticalCVSS 10.0No exploitEPSS 16%mailenable · imapdMay 2, 2005
- CVE-2006-660542Plan
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterpr
CriticalCVSS 10.0No exploitEPSS 6%mailenable · mailenable enterpriseDec 19, 2006
- CVE-2006-179241Plan
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Ed
CriticalCVSS 10.0No exploitEPSS 2%mailenable · mailenable enterpriseApr 15, 2006
- CVE-2015-928041Plan
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
CriticalCVSS 10.0No exploitEPSS 2%mailenable · mailenableJan 16, 2019
- CVE-2006-699741Plan
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enter
CriticalCVSS 10.0No exploitEPSS 2%mailenable · mailenable enterpriseFeb 12, 2007
- CVE-2007-130140Plan
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authentica
CriticalCVSS 9.0Proof of conceptEPSS 12%mailenable · mailenable enterpriseMar 6, 2007
- CVE-2015-927840Plan
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB a
CriticalCVSS 9.8No exploitEPSS 2%mailenable · mailenableJan 16, 2019
- CVE-2005-222240Plan
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 1%mailenable · mailenable professionalJul 12, 2005
- CVE-2006-517739Monitor
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecif
CriticalCVSS 9.3Proof of conceptEPSS 7%mailenable · mailenable enterpriseOct 10, 2006
- CVE-2006-517639Monitor
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code v
CriticalCVSS 9.3No exploitEPSS 5%mailenable · mailenable enterpriseOct 10, 2006
- CVE-2019-1292439Monitor
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthentica
CriticalCVSS 9.8No exploitEPSS 1%mailenable · mailenableJul 8, 2019
- CVE-2008-127738Monitor
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a
CriticalCVSS 9.0Proof of conceptEPSS 8%mailenable · mailenable enterpriseMar 10, 2008
- CVE-2008-127638Monitor
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow
CriticalCVSS 9.0Proof of conceptEPSS 7%mailenable · mailenable enterpriseMar 10, 2008
- CVE-2015-927737Monitor
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../
CriticalCVSS 9.1No exploitEPSS 2%mailenable · mailenableJan 16, 2019
- CVE-2005-222335Monitor
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a d
MediumCVSS 5.0No exploitEPSS 51%mailenable · mailenable professionalJul 12, 2005
- CVE-2019-1292635Monitor
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.
HighCVSS 8.8No exploitEPSS 1%mailenable · mailenableJul 8, 2019
- CVE-2022-4213635Monitor
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pe
HighCVSS 8.8No exploitEPSS 1%mailenable · mailenableJan 13, 2023
- CVE-2004-250134Monitor
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute a
HighCVSS 7.5Proof of conceptEPSS 14%mailenable · mailenable enterpriseDec 31, 2004
- CVE-2026-4440034Monitor
MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdmin
HighCVSS 8.7No exploitEPSS 1%mailenable · mailenableMay 8, 2026
- CVE-2025-3442134Monitor
MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLL
HighCVSS 8.5No exploitEPSS 0%mailenable · mailenableDec 10, 2025