Записи altn
25 опубликованных записей вендора altn.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 4 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
25 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
43В плане | CVE-2008-1358Готовый эксплойт | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary coaltn · mdaemon · CWE-119 | Средняя6,5 | — | 57,1 % | 17 мар. 2008 г. |
39Наблюдать | CVE-2022-37242Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.altn · security gateway for email servers · CWE-74 | Критическая9,8 | — | 1,4 % | 25 авг. 2022 г. |
39Наблюдать | CVE-2022-37240Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.altn · security gateway for email servers · CWE-74 | Критическая9,8 | — | 1,4 % | 25 авг. 2022 г. |
35Наблюдать | CVE-2021-27182Эксплойта нет | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-74 | Высокая8,8 | — | 1,6 % | 14 апр. 2021 г. |
35Наблюдать | CVE-2018-17792Эксплойта нет | MDaemon Webmail (formerly WorldClient) has CSRF.altn · mdaemon webmail · CWE-352 | Высокая8,8 | — | 1,0 % | 19 июл. 2019 г. |
35Наблюдать | CVE-2021-27181Эксплойта нет | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-352 | Высокая8,8 | — | 0,7 % | 14 апр. 2021 г. |
30Наблюдать | CVE-2019-13612Эксплойта нет | MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MBaltn · mdaemon email server · CWE-20 | Высокая7,5 | — | 1,3 % | 16 июл. 2019 г. |
29Наблюдать | CVE-2021-27183Эксплойта нет | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-610 | Высокая7,2 | — | 2,7 % | 14 апр. 2021 г. |
27Наблюдать | CVE-2008-2631Proof of concept | The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference altn · mdaemon · CWE-399 | Средняя5,0 | — | 22,8 % | 9 июн. 2008 г. |
24Наблюдать | CVE-2021-27180Proof of concept | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-79 | Средняя6,1 | — | 0,9 % | 14 апр. 2021 г. |
24Наблюдать | CVE-2019-8983Эксплойта нет | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).altn · mdaemon · CWE-79 | Средняя6,1 | — | 0,8 % | 21 февр. 2019 г. |
24Наблюдать | CVE-2019-8984Эксплойта нет | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).altn · mdaemon · CWE-79 | Средняя6,1 | — | 0,8 % | 21 февр. 2019 г. |
23Наблюдать | CVE-2022-25356Proof of concept | Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.altn · securitygateway · CWE-91 | Средняя5,3 | — | 5,7 % | 4 апр. 2022 г. |
22Наблюдать | CVE-2020-18723Proof of concept | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipiealtn · mdaemon webmail · CWE-79 | Средняя5,4 | — | 3,8 % | 3 февр. 2021 г. |
22Наблюдать | CVE-2020-18724Proof of concept | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacaltn · mdaemon webmail · CWE-79 | Средняя5,4 | — | 3,2 % | 3 февр. 2021 г. |
21Наблюдать | CVE-2022-37245Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.altn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,6 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2022-37239Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.altn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,6 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2022-37241Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoinaltn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,6 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2022-37243Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.altn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,6 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2019-19497Эксплойта нет | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.altn · mdaemon email server · CWE-79 | Средняя5,4 | — | 0,6 % | 17 дек. 2019 г. |
21Наблюдать | CVE-2022-37244Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter.altn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,5 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2022-37238Эксплойта нет | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.altn · security gateway for email servers · CWE-79 | Средняя5,4 | — | 0,5 % | 25 авг. 2022 г. |
21Наблюдать | CVE-2022-29976Эксплойта нет | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .altn · mdaemon · CWE-79 | Средняя5,4 | — | 0,5 % | 11 мая 2022 г. |
21Наблюдать | CVE-2022-29975Эксплойта нет | An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .altn · mdaemon · CWE-79 | Средняя5,4 | — | 0,5 % | 11 мая 2022 г. |
18Наблюдать | CVE-2012-2584Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTaltn · mdaemon · CWE-79 | Средняя4,3 | — | 3,2 % | 12 авг. 2012 г. |
- CVE-2008-135843В плане
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary co
СредняяCVSS 6,5Готовый эксплойтEPSS 57 %altn · mdaemon17 мар. 2008 г.
- CVE-2022-3724239Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-3724039Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2021-2718235Наблюдать
An issue was discovered in MDaemon before 20.0.4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %altn · mdaemon14 апр. 2021 г.
- CVE-2018-1779235Наблюдать
MDaemon Webmail (formerly WorldClient) has CSRF.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %altn · mdaemon webmail19 июл. 2019 г.
- CVE-2021-2718135Наблюдать
An issue was discovered in MDaemon before 20.0.4.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %altn · mdaemon14 апр. 2021 г.
- CVE-2019-1361230Наблюдать
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %altn · mdaemon email server16 июл. 2019 г.
- CVE-2021-2718329Наблюдать
An issue was discovered in MDaemon before 20.0.4.
ВысокаяCVSS 7,2Эксплойта нетEPSS 3 %altn · mdaemon14 апр. 2021 г.
- CVE-2008-263127Наблюдать
The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference
СредняяCVSS 5,0Proof of conceptEPSS 23 %altn · mdaemon9 июн. 2008 г.
- CVE-2021-2718024Наблюдать
An issue was discovered in MDaemon before 20.0.4.
СредняяCVSS 6,1Proof of conceptEPSS 1 %altn · mdaemon14 апр. 2021 г.
- CVE-2019-898324Наблюдать
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %altn · mdaemon21 февр. 2019 г.
- CVE-2019-898424Наблюдать
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
СредняяCVSS 6,1Эксплойта нетEPSS 1 %altn · mdaemon21 февр. 2019 г.
- CVE-2022-2535623Наблюдать
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
СредняяCVSS 5,3Proof of conceptEPSS 6 %altn · securitygateway4 апр. 2022 г.
- CVE-2020-1872322Наблюдать
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipie
СредняяCVSS 5,4Proof of conceptEPSS 4 %altn · mdaemon webmail3 февр. 2021 г.
- CVE-2020-1872422Наблюдать
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attac
СредняяCVSS 5,4Proof of conceptEPSS 3 %altn · mdaemon webmail3 февр. 2021 г.
- CVE-2022-3724521Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-3723921Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-3724121Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoin
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-3724321Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2019-1949721Наблюдать
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · mdaemon email server17 дек. 2019 г.
- CVE-2022-3724421Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-3723821Наблюдать
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
СредняяCVSS 5,4Эксплойта нетEPSS 1 %altn · security gateway for email servers25 авг. 2022 г.
- CVE-2022-2997621Наблюдать
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
СредняяCVSS 5,4Эксплойта нетEPSS 0 %altn · mdaemon11 мая 2022 г.
- CVE-2022-2997521Наблюдать
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .
СредняяCVSS 5,4Эксплойта нетEPSS 0 %altn · mdaemon11 мая 2022 г.
- CVE-2012-258418Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HT
СредняяCVSS 4,3Proof of conceptEPSS 3 %altn · mdaemon12 авг. 2012 г.