mailscanner records
10 published records for vendor mailscanner.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-59 Improper Link Resolution Before File Access ('Link Following')3
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-311 Missing Encryption of Sensitive Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2008-5991Proof of concept | Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute mailscanner · mailscanner · CWE-22 | High7.5 | — | 5.9% | Jan 28, 2009 |
30Monitor | CVE-2005-1706No exploit | Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers mailscanner · mailscanner | High7.5 | — | 1.4% | May 24, 2005 |
30Monitor | CVE-2005-3470No exploit | SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary mailscanner · mailscanner | High7.5 | — | 1.3% | Nov 2, 2005 |
27Monitor | CVE-2008-5313No exploit | mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain mailscanner · mailscanner · CWE-59 | Medium6.9 | — | 0.3% | Dec 3, 2008 |
27Monitor | CVE-2008-5312No exploit | mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certainmailscanner · mailscanner · CWE-59 | Medium6.9 | — | 0.3% | Dec 3, 2008 |
25Monitor | CVE-2002-2228No exploit | MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra lemailscanner · mailscanner · CWE-20 | Medium6.4 | — | 1.1% | Dec 31, 2002 |
22Monitor | CVE-2010-3293No exploit | mailscanner can allow local users to prevent virus signatures from being updatedmailscanner · mailscanner · CWE-20 | Medium5.5 | — | 0.4% | Oct 28, 2019 |
22Monitor | CVE-2010-3292No exploit | The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or mailscanner · mailscanner · CWE-311 | Medium5.5 | — | 0.2% | Nov 12, 2019 |
21Monitor | CVE-2005-3471No exploit | Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files.mailscanner · mailscanner | Medium5.0 | — | 1.7% | Nov 2, 2005 |
18Monitor | CVE-2010-3095No exploit | mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files.mailscanner · mailscanner · CWE-59 | Medium4.7 | — | 0.3% | Nov 12, 2019 |
- CVE-2008-599132Monitor
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to include and execute
HighCVSS 7.5Proof of conceptEPSS 6%mailscanner · mailscannerJan 28, 2009
- CVE-2005-170630Monitor
Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers
HighCVSS 7.5No exploitEPSS 1%mailscanner · mailscannerMay 24, 2005
- CVE-2005-347030Monitor
SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary
HighCVSS 7.5No exploitEPSS 1%mailscanner · mailscannerNov 2, 2005
- CVE-2008-531327Monitor
mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain
MediumCVSS 6.9No exploitEPSS 0%mailscanner · mailscannerDec 3, 2008
- CVE-2008-531227Monitor
mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain
MediumCVSS 6.9No exploitEPSS 0%mailscanner · mailscannerDec 3, 2008
- CVE-2002-222825Monitor
MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra le
MediumCVSS 6.4No exploitEPSS 1%mailscanner · mailscannerDec 31, 2002
- CVE-2010-329322Monitor
mailscanner can allow local users to prevent virus signatures from being updated
MediumCVSS 5.5No exploitEPSS 0%mailscanner · mailscannerOct 28, 2019
- CVE-2010-329222Monitor
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or
MediumCVSS 5.5No exploitEPSS 0%mailscanner · mailscannerNov 12, 2019
- CVE-2005-347121Monitor
Directory traversal vulnerability in the ruleset view for MailWatch for MailScanner 1.0.2 allows remote attackers to access arbitrary files.
MediumCVSS 5.0No exploitEPSS 2%mailscanner · mailscannerNov 2, 2005
- CVE-2010-309518Monitor
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files.
MediumCVSS 4.7No exploitEPSS 0%mailscanner · mailscannerNov 12, 2019