Записи kerio
44 опубликованных записей вендора kerio.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,3 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
- CWE-16 Configuration1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
44 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
51В плане | CVE-2003-0220Готовый эксплойт | Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to ekerio · personal firewall 2 | Высокая7,5 | — | 69,1 % | 12 мая 2003 г. |
41В плане | CVE-2007-3993Эксплойта нет | Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.kerio · kerio mailserver | Критическая10,0 | — | 1,8 % | 25 июл. 2007 г. |
41В плане | CVE-2004-2441Эксплойта нет | Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential seckerio · kerio mailserver | Критическая10,0 | — | 1,7 % | 31 дек. 2004 г. |
40В плане | CVE-2008-0860Эксплойта нет | Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors relatekerio · avg plugin | Критическая10,0 | — | 1,5 % | 20 февр. 2008 г. |
33Наблюдать | CVE-2003-0487Proof of concept | Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitkerio · kerio mailserver | Высокая7,5 | — | 11,4 % | 7 авг. 2003 г. |
32Наблюдать | CVE-2006-1158Эксплойта нет | Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN commkerio · kerio mailserver | Высокая7,8 | — | 2,1 % | 12 мар. 2006 г. |
32Наблюдать | CVE-2005-4425Эксплойта нет | Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain Rkerio · winroute firewall | Высокая7,8 | — | 1,8 % | 20 дек. 2005 г. |
31Наблюдать | CVE-2008-0858Эксплойта нет | Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code vikerio · kerio mailserver · CWE-94 | Высокая7,5 | — | 4,0 % | 20 февр. 2008 г. |
31Наблюдать | CVE-2003-0219Эксплойта нет | Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid skerio · personal firewall 2 | Высокая7,5 | — | 3,8 % | 12 мая 2003 г. |
31Наблюдать | CVE-2005-1062Эксплойта нет | The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allokerio · kerio mailserver | Высокая7,5 | — | 2,6 % | 2 мая 2005 г. |
31Наблюдать | CVE-2003-1491Эксплойта нет | Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to bkerio · personal firewall · CWE-16 | Высокая7,5 | — | 2,4 % | 31 дек. 2003 г. |
31Наблюдать | CVE-2005-4157Эксплойта нет | Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account thkerio · winroute firewall | Высокая7,5 | — | 1,7 % | 10 дек. 2005 г. |
28Наблюдать | CVE-2002-1434Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML sckerio · kerio mailserver | Средняя6,8 | — | 4,3 % | 11 апр. 2003 г. |
28Наблюдать | CVE-2011-1506Эксплойта нет | The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-kerio · connect · CWE-20 | Средняя6,8 | — | 2,5 % | 22 мар. 2011 г. |
28Наблюдать | CVE-2004-2329Эксплойта нет | Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall kerio · personal firewall | Высокая7,2 | — | 0,6 % | 31 дек. 2004 г. |
27Наблюдать | CVE-2014-3857Proof of concept | Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote akerio · control · CWE-89 | Средняя6,5 | — | 2,2 % | 3 июл. 2014 г. |
26Наблюдать | CVE-2004-2483Эксплойта нет | Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison thekerio · winroute firewall | Средняя6,4 | — | 1,7 % | 31 дек. 2004 г. |
25Наблюдать | CVE-2006-2203Эксплойта нет | Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of attkerio · kerio mailserver | Средняя6,4 | — | 1,2 % | 5 мая 2006 г. |
24Наблюдать | CVE-2006-6131Proof of concept | Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier alkerio · webstar | Средняя6,2 | — | 0,9 % | 27 нояб. 2006 г. |
22Наблюдать | CVE-2003-0488Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) kerio · kerio mailserver | Средняя5,1 | — | 6,8 % | 7 авг. 2003 г. |
21Наблюдать | CVE-2004-1109Proof of concept | The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and kerio · personal firewall | Средняя5,0 | — | 3,2 % | 10 янв. 2005 г. |
21Наблюдать | CVE-2006-2267Эксплойта нет | Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "emkerio · winroute firewall | Средняя5,0 | — | 3,2 % | 9 мая 2006 г. |
21Наблюдать | CVE-2006-0335Эксплойта нет | Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service viakerio · winroute firewall | Средняя5,0 | — | 2,7 % | 20 янв. 2006 г. |
21Наблюдать | CVE-2006-5420Эксплойта нет | Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.kerio · winroute firewall | Средняя5,0 | — | 2,6 % | 20 окт. 2006 г. |
21Наблюдать | CVE-2006-0336Эксплойта нет | Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors inkerio · winroute firewall | Средняя5,0 | — | 2,0 % | 20 янв. 2006 г. |
- CVE-2003-022051В плане
Buffer overflow in the administrator authentication process for Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to e
ВысокаяCVSS 7,5Готовый эксплойтEPSS 69 %kerio · personal firewall 212 мая 2003 г.
- CVE-2007-399341В плане
Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %kerio · kerio mailserver25 июл. 2007 г.
- CVE-2004-244141В плане
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential sec
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %kerio · kerio mailserver31 дек. 2004 г.
- CVE-2008-086040В плане
Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors relate
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %kerio · avg plugin20 февр. 2008 г.
- CVE-2003-048733Наблюдать
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbit
ВысокаяCVSS 7,5Proof of conceptEPSS 11 %kerio · kerio mailserver7 авг. 2003 г.
- CVE-2006-115832Наблюдать
Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN comm
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %kerio · kerio mailserver12 мар. 2006 г.
- CVE-2005-442532Наблюдать
Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain R
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %kerio · winroute firewall20 дек. 2005 г.
- CVE-2008-085831Наблюдать
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code vi
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %kerio · kerio mailserver20 февр. 2008 г.
- CVE-2003-021931Наблюдать
Kerio Personal Firewall (KPF) 2.1.4 and earlier allows remote attackers to execute administrator commands by sniffing packets from a valid s
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %kerio · personal firewall 212 мая 2003 г.
- CVE-2005-106231Наблюдать
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allo
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %kerio · kerio mailserver2 мая 2005 г.
- CVE-2003-149131Наблюдать
Kerio Personal Firewall (KPF) 2.1.4 has a default rule to accept incoming packets from DNS (UDP port 53), which allows remote attackers to b
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %kerio · personal firewall31 дек. 2003 г.
- CVE-2005-415731Наблюдать
Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to authenticate to the service using an account th
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %kerio · winroute firewall10 дек. 2005 г.
- CVE-2002-143428Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML sc
СредняяCVSS 6,8Proof of conceptEPSS 4 %kerio · kerio mailserver11 апр. 2003 г.
- CVE-2011-150628Наблюдать
The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-
СредняяCVSS 6,8Эксплойта нетEPSS 2 %kerio · connect22 мар. 2011 г.
- CVE-2004-232928Наблюдать
Kerio Personal Firewall (KPF) 2.1.5 allows local users to execute arbitrary code with SYSTEM privileges via the Load button in the Firewall
ВысокаяCVSS 7,2Эксплойта нетEPSS 1 %kerio · personal firewall31 дек. 2004 г.
- CVE-2014-385727Наблюдать
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote a
СредняяCVSS 6,5Proof of conceptEPSS 2 %kerio · control3 июл. 2014 г.
- CVE-2004-248326Наблюдать
Kerio WinRoute Firewall before 6.0.9 uses information from PTR queries in response to A queries, which allows remote attackers to poison the
СредняяCVSS 6,4Эксплойта нетEPSS 2 %kerio · winroute firewall31 дек. 2004 г.
- CVE-2006-220325Наблюдать
Unspecified vulnerability in Kerio MailServer before 6.1.4 has unknown impact and remote attack vectors related to a "possible bypass of att
СредняяCVSS 6,4Эксплойта нетEPSS 1 %kerio · kerio mailserver5 мая 2006 г.
- CVE-2006-613124Наблюдать
Untrusted search path vulnerability in (1) WSAdminServer and (2) WSWebServer in Kerio WebSTAR (4D WebSTAR Server Suite) 5.4.2 and earlier al
СредняяCVSS 6,2Proof of conceptEPSS 1 %kerio · webstar27 нояб. 2006 г.
- CVE-2003-048822Наблюдать
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1)
СредняяCVSS 5,1Proof of conceptEPSS 7 %kerio · kerio mailserver7 авг. 2003 г.
- CVE-2004-110921Наблюдать
The FWDRV.SYS driver in Kerio Personal Firewall 4.1.1 and earlier allows remote attackers to cause a denial of service (CPU consumption and
СредняяCVSS 5,0Proof of conceptEPSS 3 %kerio · personal firewall10 янв. 2005 г.
- CVE-2006-226721Наблюдать
Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "em
СредняяCVSS 5,0Эксплойта нетEPSS 3 %kerio · winroute firewall9 мая 2006 г.
- CVE-2006-033521Наблюдать
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via
СредняяCVSS 5,0Эксплойта нетEPSS 3 %kerio · winroute firewall20 янв. 2006 г.
- CVE-2006-542021Наблюдать
Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.
СредняяCVSS 5,0Эксплойта нетEPSS 3 %kerio · winroute firewall20 окт. 2006 г.
- CVE-2006-033621Наблюдать
Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors in
СредняяCVSS 5,0Эксплойта нетEPSS 2 %kerio · winroute firewall20 янв. 2006 г.