Записи MailEnable
90 опубликованных записей вендора mailenable.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 4 · 4,4 %
- Pre-auth RCE
- 26
- С записью об исправлении
- 2,2 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-427 Uncontrolled Search Path Element10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-399 Resource Management Errors3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
90 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
61На этой неделе | CVE-2006-6423Готовый эксплойт | Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.mailenable · mailenable enterprise | Критическая10,0 | — | 70,7 % | 11 дек. 2006 г. |
55В плане | CVE-2025-44148Proof of concept | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx comailenable · mailenable · CWE-79 | Критическая9,8 | — | 54,7 % | 3 июн. 2025 г. |
53В плане | CVE-2005-2278Готовый эксплойт | Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrarmailenable · mailenable professional | Высокая7,2 | — | 84,6 % | 18 июл. 2005 г. |
52В плане | CVE-2005-1348Готовый эксплойт | Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute amailenable · mailenable enterprise | Высокая7,5 | — | 72,6 % | 2 мая 2005 г. |
49В плане | CVE-2005-3155Готовый эксплойт | Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.mailenable · mailenable enterprise | Высокая7,5 | — | 63,7 % | 5 окт. 2005 г. |
45В плане | CVE-2005-1015Эксплойта нет | Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.mailenable · imapd | Критическая10,0 | — | 16,2 % | 2 мая 2005 г. |
42В плане | CVE-2006-6605Эксплойта нет | Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprmailenable · mailenable enterprise | Критическая10,0 | — | 5,9 % | 19 дек. 2006 г. |
41В плане | CVE-2006-1792Эксплойта нет | Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edmailenable · mailenable enterprise | Критическая10,0 | — | 1,9 % | 15 апр. 2006 г. |
41В плане | CVE-2015-9280Эксплойта нет | MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.mailenable · mailenable · CWE-611 | Критическая10,0 | — | 1,8 % | 16 янв. 2019 г. |
41В плане | CVE-2006-6997Эксплойта нет | Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Entermailenable · mailenable enterprise · CWE-287 | Критическая10,0 | — | 1,8 % | 12 февр. 2007 г. |
40В плане | CVE-2007-1301Proof of concept | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticamailenable · mailenable enterprise | Критическая9,0 | — | 12,2 % | 6 мар. 2007 г. |
40В плане | CVE-2015-9278Эксплойта нет | MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB amailenable · mailenable · CWE-255 | Критическая9,8 | — | 2,5 % | 16 янв. 2019 г. |
40В плане | CVE-2005-2222Эксплойта нет | Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.mailenable · mailenable professional | Критическая10,0 | — | 1,4 % | 12 июл. 2005 г. |
39Наблюдать | CVE-2006-5177Proof of concept | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecifmailenable · mailenable enterprise · CWE-119 | Критическая9,3 | — | 7,1 % | 10 окт. 2006 г. |
39Наблюдать | CVE-2006-5176Эксплойта нет | Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code vmailenable · mailenable enterprise · CWE-119 | Критическая9,3 | — | 5,4 % | 10 окт. 2006 г. |
39Наблюдать | CVE-2019-12924Эксплойта нет | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticamailenable · mailenable · CWE-311 | Критическая9,8 | — | 0,9 % | 8 июл. 2019 г. |
38Наблюдать | CVE-2008-1277Proof of concept | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause amailenable · mailenable enterprise · CWE-20 | Критическая9,0 | — | 8,3 % | 10 мар. 2008 г. |
38Наблюдать | CVE-2008-1276Proof of concept | Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allowmailenable · mailenable enterprise · CWE-119 | Критическая9,0 | — | 7,1 % | 10 мар. 2008 г. |
37Наблюдать | CVE-2015-9277Эксплойта нет | MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../mailenable · mailenable · CWE-22 | Критическая9,1 | — | 2,2 % | 16 янв. 2019 г. |
35Наблюдать | CVE-2005-2223Эксплойта нет | Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a dmailenable · mailenable professional | Средняя5,0 | — | 50,8 % | 12 июл. 2005 г. |
35Наблюдать | CVE-2019-12926Эксплойта нет | MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.mailenable · mailenable · CWE-862 | Высокая8,8 | — | 0,9 % | 8 июл. 2019 г. |
35Наблюдать | CVE-2022-42136Эксплойта нет | Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pemailenable · mailenable · CWE-22 | Высокая8,8 | — | 0,9 % | 13 янв. 2023 г. |
34Наблюдать | CVE-2004-2501Proof of concept | Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute amailenable · mailenable enterprise | Высокая7,5 | — | 14,1 % | 31 дек. 2004 г. |
34Наблюдать | CVE-2026-44400Эксплойта нет | MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdminmailenable · mailenable · CWE-639 | Высокая8,7 | — | 0,6 % | 8 мая 2026 г. |
34Наблюдать | CVE-2025-34421Эксплойта нет | MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLLmailenable · mailenable · CWE-427 | Высокая8,5 | — | 0,2 % | 10 дек. 2025 г. |
- CVE-2006-642361На этой неделе
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.
КритическаяCVSS 10,0Готовый эксплойтEPSS 71 %mailenable · mailenable enterprise11 дек. 2006 г.
- CVE-2025-4414855В плане
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx co
КритическаяCVSS 9,8Proof of conceptEPSS 55 %mailenable · mailenable3 июн. 2025 г.
- CVE-2005-227853В плане
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrar
ВысокаяCVSS 7,2Готовый эксплойтEPSS 85 %mailenable · mailenable professional18 июл. 2005 г.
- CVE-2005-134852В плане
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute a
ВысокаяCVSS 7,5Готовый эксплойтEPSS 73 %mailenable · mailenable enterprise2 мая 2005 г.
- CVE-2005-315549В плане
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
ВысокаяCVSS 7,5Готовый эксплойтEPSS 64 %mailenable · mailenable enterprise5 окт. 2005 г.
- CVE-2005-101545В плане
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
КритическаяCVSS 10,0Эксплойта нетEPSS 16 %mailenable · imapd2 мая 2005 г.
- CVE-2006-660542В плане
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterpr
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %mailenable · mailenable enterprise19 дек. 2006 г.
- CVE-2006-179241В плане
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Ed
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mailenable · mailenable enterprise15 апр. 2006 г.
- CVE-2015-928041В плане
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mailenable · mailenable16 янв. 2019 г.
- CVE-2006-699741В плане
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enter
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %mailenable · mailenable enterprise12 февр. 2007 г.
- CVE-2007-130140В плане
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authentica
КритическаяCVSS 9,0Proof of conceptEPSS 12 %mailenable · mailenable enterprise6 мар. 2007 г.
- CVE-2015-927840В плане
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB a
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %mailenable · mailenable16 янв. 2019 г.
- CVE-2005-222240В плане
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %mailenable · mailenable professional12 июл. 2005 г.
- CVE-2006-517739Наблюдать
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecif
КритическаяCVSS 9,3Proof of conceptEPSS 7 %mailenable · mailenable enterprise10 окт. 2006 г.
- CVE-2006-517639Наблюдать
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code v
КритическаяCVSS 9,3Эксплойта нетEPSS 5 %mailenable · mailenable enterprise10 окт. 2006 г.
- CVE-2019-1292439Наблюдать
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthentica
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %mailenable · mailenable8 июл. 2019 г.
- CVE-2008-127738Наблюдать
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a
КритическаяCVSS 9,0Proof of conceptEPSS 8 %mailenable · mailenable enterprise10 мар. 2008 г.
- CVE-2008-127638Наблюдать
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow
КритическаяCVSS 9,0Proof of conceptEPSS 7 %mailenable · mailenable enterprise10 мар. 2008 г.
- CVE-2015-927737Наблюдать
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %mailenable · mailenable16 янв. 2019 г.
- CVE-2005-222335Наблюдать
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a d
СредняяCVSS 5,0Эксплойта нетEPSS 51 %mailenable · mailenable professional12 июл. 2005 г.
- CVE-2019-1292635Наблюдать
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mailenable · mailenable8 июл. 2019 г.
- CVE-2022-4213635Наблюдать
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pe
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %mailenable · mailenable13 янв. 2023 г.
- CVE-2004-250134Наблюдать
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute a
ВысокаяCVSS 7,5Proof of conceptEPSS 14 %mailenable · mailenable enterprise31 дек. 2004 г.
- CVE-2026-4440034Наблюдать
MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdmin
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mailenable · mailenable8 мая 2026 г.
- CVE-2025-3442134Наблюдать
MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLL
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %mailenable · mailenable10 дек. 2025 г.