IceWarp kayıtları
icewarp üreticisine ait 70 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')27
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
70 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
47Planlayın | CVE-2015-1503Kavram kanıtı | Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) ..icewarp · mail server · CWE-22 | Yüksek7,5 | — | %57,6 | 8 May 2018 |
42Planlayın | CVE-2019-12593Kavram kanıtı | IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c diricewarp · mail server · CWE-22 | Yüksek7,5 | — | %41,0 | 3 Haz 2019 |
39İzleyin | CVE-2023-39699İstismar yok | IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/indexicewarp · mail server · CWE-22 | Kritik9,8 | — | %1,4 | 24 Ağu 2023 |
39İzleyin | CVE-2022-35115İstismar yok | IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webicewarp · webclient dc2 · CWE-89 | Kritik9,8 | — | %0,8 | 23 Ağu 2022 |
36İzleyin | CVE-2020-14066Kavram kanıtı | IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.icewarp · mail server · CWE-434 | Yüksek8,8 | — | %1,8 | 15 Tem 2020 |
33İzleyin | CVE-2005-4556Kavram kanıtı | PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 icewarp · web mail | Yüksek7,5 | — | %10,6 | 28 Ara 2005 |
31İzleyin | CVE-2009-1516Kavram kanıtı | Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow contexticewarp · merak mail server · CWE-119 | Yüksek7,5 | — | %3,2 | 4 May 2009 |
31İzleyin | CVE-2010-5335İstismar yok | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability.icewarp · webclient · CWE-22 | Yüksek7,5 | — | %2,8 | 11 Eki 2019 |
31İzleyin | CVE-2010-5334İstismar yok | IceWarp Webclient before 10.2.1 has a directory traversal vulnerability.icewarp · webclient · CWE-22 | Yüksek7,5 | — | %2,6 | 11 Eki 2019 |
31İzleyin | CVE-2004-1670İstismar yok | Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote icewarp · web mail | Yüksek7,5 | — | %1,8 | 10 Eyl 2004 |
31İzleyin | CVE-2004-1673İstismar yok | accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to createicewarp · web mail | Yüksek7,5 | — | %1,7 | 12 Eki 2004 |
31İzleyin | CVE-2004-1672İstismar yok | attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other useicewarp · web mail | Yüksek7,5 | — | %1,7 | 12 Eki 2004 |
30İzleyin | CVE-2004-1674İstismar yok | viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbicewarp · web mail | Yüksek7,5 | — | %1,5 | 12 Eki 2004 |
30İzleyin | CVE-2002-0258İstismar yok | Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote atticewarp · web mail | Yüksek7,5 | — | %1,4 | 29 May 2002 |
29İzleyin | CVE-2005-4558Kavram kanıtı | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict accepicewarp · web mail | Orta6,5 | — | %8,5 | 28 Ara 2005 |
28İzleyin | CVE-2020-8512Kavram kanıtı | In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.icewarp · icewarp server · CWE-79 | Orta6,1 | — | %14,8 | 31 Oca 2020 |
28İzleyin | CVE-2005-0322İstismar yok | MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) usicewarp · web mail | Yüksek7,2 | — | %0,2 | 2 May 2005 |
27İzleyin | CVE-2009-1468Kavram kanıtı | Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMaicewarp · email server · CWE-89 | Orta6,5 | — | %1,9 | 5 May 2009 |
26İzleyin | CVE-2020-27982Kavram kanıtı | IceWarp 11.4.5.0 allows XSS via the language parameter.icewarp · mail server · CWE-79 | Orta6,1 | — | %5,3 | 2 Kas 2020 |
26İzleyin | CVE-2011-3579Kavram kanıtı | server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly senicewarp · mail server · CWE-399 | Orta6,4 | — | %4,8 | 30 Eyl 2011 |
26İzleyin | CVE-2020-14065Kavram kanıtı | IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.icewarp · mail server · CWE-434 | Orta6,5 | — | %1,5 | 15 Tem 2020 |
26İzleyin | CVE-2020-14064Kavram kanıtı | IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.icewarp · mail server · CWE-668 | Orta6,5 | — | %1,0 | 15 Tem 2020 |
25İzleyin | CVE-2017-7855Kavram kanıtı | In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.icewarp · server · CWE-79 | Orta6,1 | — | %2,0 | 31 Ağu 2017 |
24İzleyin | CVE-2021-36580Kavram kanıtı | Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.icewarp · icewarp server · CWE-601 | Orta6,1 | — | %1,6 | 27 Tem 2023 |
24İzleyin | CVE-2023-39700Kavram kanıtı | IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.icewarp · mail server · CWE-79 | Orta6,1 | — | %1,5 | 24 Ağu 2023 |
- CVE-2015-150347Planlayın
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) ..
YüksekCVSS 7,5Kavram kanıtıEPSS %58icewarp · mail server8 May 2018
- CVE-2019-1259342Planlayın
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c dir
YüksekCVSS 7,5Kavram kanıtıEPSS %41icewarp · mail server3 Haz 2019
- CVE-2023-3969939İzleyin
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index
KritikCVSS 9,8İstismar yokEPSS %1icewarp · mail server24 Ağu 2023
- CVE-2022-3511539İzleyin
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /web
KritikCVSS 9,8İstismar yokEPSS %1icewarp · webclient dc223 Ağu 2022
- CVE-2020-1406636İzleyin
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
YüksekCVSS 8,8Kavram kanıtıEPSS %2icewarp · mail server15 Tem 2020
- CVE-2005-455633İzleyin
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0
YüksekCVSS 7,5Kavram kanıtıEPSS %11icewarp · web mail28 Ara 2005
- CVE-2009-151631İzleyin
Stack-based buffer overflow in the IceWarpServer.APIObject ActiveX control in api.dll in IceWarp Merak Mail Server 9.4.1 might allow context
YüksekCVSS 7,5Kavram kanıtıEPSS %3icewarp · merak mail server4 May 2009
- CVE-2010-533531İzleyin
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %3icewarp · webclient11 Eki 2019
- CVE-2010-533431İzleyin
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability.
YüksekCVSS 7,5İstismar yokEPSS %3icewarp · webclient11 Eki 2019
- CVE-2004-167031İzleyin
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote
YüksekCVSS 7,5İstismar yokEPSS %2icewarp · web mail10 Eyl 2004
- CVE-2004-167331İzleyin
accountsettings_add.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allow remote attackers to create
YüksekCVSS 7,5İstismar yokEPSS %2icewarp · web mail12 Eki 2004
- CVE-2004-167231İzleyin
attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other use
YüksekCVSS 7,5İstismar yokEPSS %2icewarp · web mail12 Eki 2004
- CVE-2004-167430İzleyin
viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arb
YüksekCVSS 7,5İstismar yokEPSS %2icewarp · web mail12 Eki 2004
- CVE-2002-025830İzleyin
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote att
YüksekCVSS 7,5İstismar yokEPSS %1icewarp · web mail29 May 2002
- CVE-2005-455829İzleyin
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict accep
OrtaCVSS 6,5Kavram kanıtıEPSS %8icewarp · web mail28 Ara 2005
- CVE-2020-851228İzleyin
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %15icewarp · icewarp server31 Oca 2020
- CVE-2005-032228İzleyin
MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) us
YüksekCVSS 7,2İstismar yokEPSS %0icewarp · web mail2 May 2005
- CVE-2009-146827İzleyin
Multiple SQL injection vulnerabilities in the search form in server/webmail.php in the Groupware component in IceWarp eMail Server and WebMa
OrtaCVSS 6,5Kavram kanıtıEPSS %2icewarp · email server5 May 2009
- CVE-2020-2798226İzleyin
IceWarp 11.4.5.0 allows XSS via the language parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %5icewarp · mail server2 Kas 2020
- CVE-2011-357926İzleyin
server/webmail.php in IceWarp WebMail in IceWarp Mail Server before 10.3.3 allows remote attackers to read arbitrary files, and possibly sen
OrtaCVSS 6,4Kavram kanıtıEPSS %5icewarp · mail server30 Eyl 2011
- CVE-2020-1406526İzleyin
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
OrtaCVSS 6,5Kavram kanıtıEPSS %1icewarp · mail server15 Tem 2020
- CVE-2020-1406426İzleyin
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
OrtaCVSS 6,5Kavram kanıtıEPSS %1icewarp · mail server15 Tem 2020
- CVE-2017-785525İzleyin
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %2icewarp · server31 Ağu 2017
- CVE-2021-3658024İzleyin
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %2icewarp · icewarp server27 Tem 2023
- CVE-2023-3970024İzleyin
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.
OrtaCVSS 6,1Kavram kanıtıEPSS %1icewarp · mail server24 Ağu 2023