MailEnable kayıtları
mailenable üreticisine ait 90 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 4 · %4,4
- Pre-auth RCE
- 26
- Düzeltme kaydı olan
- %2,2
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-427 Uncontrolled Search Path Element10
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-399 Resource Management Errors3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
90 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
61Bu hafta | CVE-2006-6423Silahlaştırılmış | Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.mailenable · mailenable enterprise | Kritik10,0 | — | %70,7 | 11 Ara 2006 |
55Planlayın | CVE-2025-44148Kavram kanıtı | Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx comailenable · mailenable · CWE-79 | Kritik9,8 | — | %54,7 | 3 Haz 2025 |
53Planlayın | CVE-2005-2278Silahlaştırılmış | Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrarmailenable · mailenable professional | Yüksek7,2 | — | %84,6 | 18 Tem 2005 |
52Planlayın | CVE-2005-1348Silahlaştırılmış | Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute amailenable · mailenable enterprise | Yüksek7,5 | — | %72,6 | 2 May 2005 |
49Planlayın | CVE-2005-3155Silahlaştırılmış | Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.mailenable · mailenable enterprise | Yüksek7,5 | — | %63,7 | 5 Eki 2005 |
45Planlayın | CVE-2005-1015İstismar yok | Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.mailenable · imapd | Kritik10,0 | — | %16,2 | 2 May 2005 |
42Planlayın | CVE-2006-6605İstismar yok | Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterprmailenable · mailenable enterprise | Kritik10,0 | — | %5,9 | 19 Ara 2006 |
41Planlayın | CVE-2006-1792İstismar yok | Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edmailenable · mailenable enterprise | Kritik10,0 | — | %1,9 | 15 Nis 2006 |
41Planlayın | CVE-2015-9280İstismar yok | MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.mailenable · mailenable · CWE-611 | Kritik10,0 | — | %1,8 | 16 Oca 2019 |
41Planlayın | CVE-2006-6997İstismar yok | Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Entermailenable · mailenable enterprise · CWE-287 | Kritik10,0 | — | %1,8 | 12 Şub 2007 |
40Planlayın | CVE-2007-1301Kavram kanıtı | Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authenticamailenable · mailenable enterprise | Kritik9,0 | — | %12,2 | 6 Mar 2007 |
40Planlayın | CVE-2015-9278İstismar yok | MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB amailenable · mailenable · CWE-255 | Kritik9,8 | — | %2,5 | 16 Oca 2019 |
40Planlayın | CVE-2005-2222İstismar yok | Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.mailenable · mailenable professional | Kritik10,0 | — | %1,4 | 12 Tem 2005 |
39İzleyin | CVE-2006-5177Kavram kanıtı | The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecifmailenable · mailenable enterprise · CWE-119 | Kritik9,3 | — | %7,1 | 10 Eki 2006 |
39İzleyin | CVE-2006-5176İstismar yok | Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code vmailenable · mailenable enterprise · CWE-119 | Kritik9,3 | — | %5,4 | 10 Eki 2006 |
39İzleyin | CVE-2019-12924İstismar yok | MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthenticamailenable · mailenable · CWE-311 | Kritik9,8 | — | %0,9 | 8 Tem 2019 |
38İzleyin | CVE-2008-1277Kavram kanıtı | The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause amailenable · mailenable enterprise · CWE-20 | Kritik9,0 | — | %8,3 | 10 Mar 2008 |
38İzleyin | CVE-2008-1276Kavram kanıtı | Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allowmailenable · mailenable enterprise · CWE-119 | Kritik9,0 | — | %7,1 | 10 Mar 2008 |
37İzleyin | CVE-2015-9277İstismar yok | MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../mailenable · mailenable · CWE-22 | Kritik9,1 | — | %2,2 | 16 Oca 2019 |
35İzleyin | CVE-2005-2223İstismar yok | Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a dmailenable · mailenable professional | Orta5,0 | — | %50,8 | 12 Tem 2005 |
35İzleyin | CVE-2019-12926İstismar yok | MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.mailenable · mailenable · CWE-862 | Yüksek8,8 | — | %0,9 | 8 Tem 2019 |
35İzleyin | CVE-2022-42136İstismar yok | Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pemailenable · mailenable · CWE-22 | Yüksek8,8 | — | %0,9 | 13 Oca 2023 |
34İzleyin | CVE-2004-2501Kavram kanıtı | Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute amailenable · mailenable enterprise | Yüksek7,5 | — | %14,1 | 31 Ara 2004 |
34İzleyin | CVE-2026-44400İstismar yok | MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdminmailenable · mailenable · CWE-639 | Yüksek8,7 | — | %0,6 | 8 May 2026 |
34İzleyin | CVE-2025-34421İstismar yok | MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLLmailenable · mailenable · CWE-427 | Yüksek8,5 | — | %0,2 | 10 Ara 2025 |
- CVE-2006-642361Bu hafta
Stack-based buffer overflow in the IMAP service for MailEnable Professional and Enterprise Edition 2.0 through 2.35, Professional Edition 1.
KritikCVSS 10,0SilahlaştırılmışEPSS %71mailenable · mailenable enterprise11 Ara 2006
- CVE-2025-4414855Planlayın
Cross Site Scripting (XSS) vulnerability in MailEnable before v10 allows a remote attacker to execute arbitrary code via the failure.aspx co
KritikCVSS 9,8Kavram kanıtıEPSS %55mailenable · mailenable3 Haz 2025
- CVE-2005-227853Planlayın
Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrar
YüksekCVSS 7,2SilahlaştırılmışEPSS %85mailenable · mailenable professional18 Tem 2005
- CVE-2005-134852Planlayın
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote attackers to execute a
YüksekCVSS 7,5SilahlaştırılmışEPSS %73mailenable · mailenable enterprise2 May 2005
- CVE-2005-315549Planlayın
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
YüksekCVSS 7,5SilahlaştırılmışEPSS %64mailenable · mailenable enterprise5 Eki 2005
- CVE-2005-101545Planlayın
Buffer overflow in MailEnable Imapd (MEIMAP.exe) allows remote attackers to execute arbitrary code via a long LOGIN command.
KritikCVSS 10,0İstismar yokEPSS %16mailenable · imapd2 May 2005
- CVE-2006-660542Planlayın
Stack-based buffer overflow in the POP service in MailEnable Standard 1.98 and earlier; Professional 1.84, and 2.35 and earlier; and Enterpr
KritikCVSS 10,0İstismar yokEPSS %6mailenable · mailenable enterprise19 Ara 2006
- CVE-2006-179241Planlayın
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Ed
KritikCVSS 10,0İstismar yokEPSS %2mailenable · mailenable enterprise15 Nis 2006
- CVE-2015-928041Planlayın
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
KritikCVSS 10,0İstismar yokEPSS %2mailenable · mailenable16 Oca 2019
- CVE-2006-699741Planlayın
Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enter
KritikCVSS 10,0İstismar yokEPSS %2mailenable · mailenable enterprise12 Şub 2007
- CVE-2007-130140Planlayın
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allows remote authentica
KritikCVSS 9,0Kavram kanıtıEPSS %12mailenable · mailenable enterprise6 Mar 2007
- CVE-2015-927840Planlayın
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB a
KritikCVSS 9,8İstismar yokEPSS %2mailenable · mailenable16 Oca 2019
- CVE-2005-222240Planlayın
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
KritikCVSS 10,0İstismar yokEPSS %1mailenable · mailenable professional12 Tem 2005
- CVE-2006-517739İzleyin
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecif
KritikCVSS 9,3Kavram kanıtıEPSS %7mailenable · mailenable enterprise10 Eki 2006
- CVE-2006-517639İzleyin
Buffer overflow in NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to execute arbitrary code v
KritikCVSS 9,3İstismar yokEPSS %5mailenable · mailenable enterprise10 Eki 2006
- CVE-2019-1292439İzleyin
MailEnable Enterprise Premium 10.23 was vulnerable to XML External Entity Injection (XXE) attacks that could be exploited by an unauthentica
KritikCVSS 9,8İstismar yokEPSS %1mailenable · mailenable8 Tem 2019
- CVE-2008-127738İzleyin
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote attackers to cause a
KritikCVSS 9,0Kavram kanıtıEPSS %8mailenable · mailenable enterprise10 Mar 2008
- CVE-2008-127638İzleyin
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allow
KritikCVSS 9,0Kavram kanıtıEPSS %7mailenable · mailenable enterprise10 Mar 2008
- CVE-2015-927737İzleyin
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../
KritikCVSS 9,1İstismar yokEPSS %2mailenable · mailenable16 Oca 2019
- CVE-2005-222335İzleyin
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a d
OrtaCVSS 5,0İstismar yokEPSS %51mailenable · mailenable professional12 Tem 2005
- CVE-2019-1292635İzleyin
MailEnable Enterprise Premium 10.23 did not use appropriate access control checks in a number of areas.
YüksekCVSS 8,8İstismar yokEPSS %1mailenable · mailenable8 Tem 2019
- CVE-2022-4213635İzleyin
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had pe
YüksekCVSS 8,8İstismar yokEPSS %1mailenable · mailenable13 Oca 2023
- CVE-2004-250134İzleyin
Buffer overflow in the IMAP service of MailEnable Professional Edition 1.52 and Enterprise Edition 1.01 allows remote attackers to execute a
YüksekCVSS 7,5Kavram kanıtıEPSS %14mailenable · mailenable enterprise31 Ara 2004
- CVE-2026-4440034İzleyin
MailEnable Enterprise Premium < 10.55 Authorization Bypass via WebAdmin
YüksekCVSS 8,7İstismar yokEPSS %1mailenable · mailenable8 May 2026
- CVE-2025-3442134İzleyin
MailEnable < 10.54 DLL Hijacking via Unsafe Loading of MEAISP.DLL
YüksekCVSS 8,5İstismar yokEPSS %0mailenable · mailenable10 Ara 2025