altn kayıtları
altn üreticisine ait 25 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %4
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')15
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')3
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-610 Externally Controlled Reference to a Resource in Another Sphere1
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-91 XML Injection (aka Blind XPath Injection)1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
25 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
43Planlayın | CVE-2008-1358Silahlaştırılmış | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary coaltn · mdaemon · CWE-119 | Orta6,5 | — | %57,1 | 17 Mar 2008 |
39İzleyin | CVE-2022-37242İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.altn · security gateway for email servers · CWE-74 | Kritik9,8 | — | %1,4 | 25 Ağu 2022 |
39İzleyin | CVE-2022-37240İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.altn · security gateway for email servers · CWE-74 | Kritik9,8 | — | %1,4 | 25 Ağu 2022 |
35İzleyin | CVE-2021-27182İstismar yok | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-74 | Yüksek8,8 | — | %1,6 | 14 Nis 2021 |
35İzleyin | CVE-2018-17792İstismar yok | MDaemon Webmail (formerly WorldClient) has CSRF.altn · mdaemon webmail · CWE-352 | Yüksek8,8 | — | %1,0 | 19 Tem 2019 |
35İzleyin | CVE-2021-27181İstismar yok | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-352 | Yüksek8,8 | — | %0,7 | 14 Nis 2021 |
30İzleyin | CVE-2019-13612İstismar yok | MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MBaltn · mdaemon email server · CWE-20 | Yüksek7,5 | — | %1,3 | 16 Tem 2019 |
29İzleyin | CVE-2021-27183İstismar yok | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-610 | Yüksek7,2 | — | %2,7 | 14 Nis 2021 |
27İzleyin | CVE-2008-2631Kavram kanıtı | The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference altn · mdaemon · CWE-399 | Orta5,0 | — | %22,8 | 9 Haz 2008 |
24İzleyin | CVE-2021-27180Kavram kanıtı | An issue was discovered in MDaemon before 20.0.4.altn · mdaemon · CWE-79 | Orta6,1 | — | %0,9 | 14 Nis 2021 |
24İzleyin | CVE-2019-8983İstismar yok | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).altn · mdaemon · CWE-79 | Orta6,1 | — | %0,8 | 21 Şub 2019 |
24İzleyin | CVE-2019-8984İstismar yok | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).altn · mdaemon · CWE-79 | Orta6,1 | — | %0,8 | 21 Şub 2019 |
23İzleyin | CVE-2022-25356Kavram kanıtı | Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.altn · securitygateway · CWE-91 | Orta5,3 | — | %5,7 | 4 Nis 2022 |
22İzleyin | CVE-2020-18723Kavram kanıtı | Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipiealtn · mdaemon webmail · CWE-79 | Orta5,4 | — | %3,8 | 3 Şub 2021 |
22İzleyin | CVE-2020-18724Kavram kanıtı | Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacaltn · mdaemon webmail · CWE-79 | Orta5,4 | — | %3,2 | 3 Şub 2021 |
21İzleyin | CVE-2022-37245İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.altn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,6 | 25 Ağu 2022 |
21İzleyin | CVE-2022-37239İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.altn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,6 | 25 Ağu 2022 |
21İzleyin | CVE-2022-37241İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoinaltn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,6 | 25 Ağu 2022 |
21İzleyin | CVE-2022-37243İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.altn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,6 | 25 Ağu 2022 |
21İzleyin | CVE-2019-19497İstismar yok | MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.altn · mdaemon email server · CWE-79 | Orta5,4 | — | %0,6 | 17 Ara 2019 |
21İzleyin | CVE-2022-37244İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter.altn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,5 | 25 Ağu 2022 |
21İzleyin | CVE-2022-37238İstismar yok | MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.altn · security gateway for email servers · CWE-79 | Orta5,4 | — | %0,5 | 25 Ağu 2022 |
21İzleyin | CVE-2022-29976İstismar yok | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .altn · mdaemon · CWE-79 | Orta5,4 | — | %0,5 | 11 May 2022 |
21İzleyin | CVE-2022-29975İstismar yok | An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .altn · mdaemon · CWE-79 | Orta5,4 | — | %0,5 | 11 May 2022 |
18İzleyin | CVE-2012-2584Kavram kanıtı | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTaltn · mdaemon · CWE-79 | Orta4,3 | — | %3,2 | 12 Ağu 2012 |
- CVE-2008-135843Planlayın
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary co
OrtaCVSS 6,5SilahlaştırılmışEPSS %57altn · mdaemon17 Mar 2008
- CVE-2022-3724239İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2, is vulnerable to HTTP Response splitting via the data parameter.
KritikCVSS 9,8İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-3724039İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to HTTP Response splitting via the format parameter.
KritikCVSS 9,8İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2021-2718235İzleyin
An issue was discovered in MDaemon before 20.0.4.
YüksekCVSS 8,8İstismar yokEPSS %2altn · mdaemon14 Nis 2021
- CVE-2018-1779235İzleyin
MDaemon Webmail (formerly WorldClient) has CSRF.
YüksekCVSS 8,8İstismar yokEPSS %1altn · mdaemon webmail19 Tem 2019
- CVE-2021-2718135İzleyin
An issue was discovered in MDaemon before 20.0.4.
YüksekCVSS 8,8İstismar yokEPSS %1altn · mdaemon14 Nis 2021
- CVE-2019-1361230İzleyin
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB
YüksekCVSS 7,5İstismar yokEPSS %1altn · mdaemon email server16 Tem 2019
- CVE-2021-2718329İzleyin
An issue was discovered in MDaemon before 20.0.4.
YüksekCVSS 7,2İstismar yokEPSS %3altn · mdaemon14 Nis 2021
- CVE-2008-263127İzleyin
The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference
OrtaCVSS 5,0Kavram kanıtıEPSS %23altn · mdaemon9 Haz 2008
- CVE-2021-2718024İzleyin
An issue was discovered in MDaemon before 20.0.4.
OrtaCVSS 6,1Kavram kanıtıEPSS %1altn · mdaemon14 Nis 2021
- CVE-2019-898324İzleyin
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
OrtaCVSS 6,1İstismar yokEPSS %1altn · mdaemon21 Şub 2019
- CVE-2019-898424İzleyin
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
OrtaCVSS 6,1İstismar yokEPSS %1altn · mdaemon21 Şub 2019
- CVE-2022-2535623İzleyin
Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection.
OrtaCVSS 5,3Kavram kanıtıEPSS %6altn · securitygateway4 Nis 2022
- CVE-2020-1872322İzleyin
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code on the email recipie
OrtaCVSS 5,4Kavram kanıtıEPSS %4altn · mdaemon webmail3 Şub 2021
- CVE-2020-1872422İzleyin
Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attac
OrtaCVSS 5,4Kavram kanıtıEPSS %3altn · mdaemon webmail3 Şub 2021
- CVE-2022-3724521İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the Blacklist endpoint.
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-3723921İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the rulles_list_ajax endpoint.
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-3724121İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the data_leak_list_ajax endpoin
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-3724321İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the whitelist endpoint.
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2019-1949721İzleyin
MDaemon Email Server 17.5.1 allows XSS via the filename of an attachment to an email message.
OrtaCVSS 5,4İstismar yokEPSS %1altn · mdaemon email server17 Ara 2019
- CVE-2022-3724421İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to IFRAME Injectionvia the currentRequest parameter.
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-3723821İzleyin
MDaemon Technologies SecurityGateway for Email Servers 8.5.2 is vulnerable to Cross Site Scripting (XSS) via the currentRequest parameter.
OrtaCVSS 5,4İstismar yokEPSS %1altn · security gateway for email servers25 Ağu 2022
- CVE-2022-2997621İzleyin
An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 .
OrtaCVSS 5,4İstismar yokEPSS %0altn · mdaemon11 May 2022
- CVE-2022-2997521İzleyin
An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 .
OrtaCVSS 5,4İstismar yokEPSS %0altn · mdaemon11 May 2022
- CVE-2012-258418İzleyin
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HT
OrtaCVSS 4,3Kavram kanıtıEPSS %3altn · mdaemon12 Ağu 2012