Lucene search

K

Mail Security Vulnerabilities

cve
cve

CVE-2020-12699

The direct_mail extension through 5.2.3 for TYPO3 has an Open Redirect via...

6.1CVSS

6.3AI Score

0.001EPSS

2020-05-13 01:15 PM
43
cve
cve

CVE-2020-12697

The direct_mail extension through 5.2.3 for TYPO3 allows Denial of Service via log...

5.3CVSS

5.5AI Score

0.001EPSS

2020-05-13 01:15 PM
35
cve
cve

CVE-2020-12698

The direct_mail extension through 5.2.3 for TYPO3 has Broken Access Control for newsletter subscriber...

4.3CVSS

4.9AI Score

0.001EPSS

2020-05-13 01:15 PM
46
cve
cve

CVE-2020-8156

A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle...

7CVSS

7AI Score

0.001EPSS

2020-05-12 01:15 PM
27
4
cve
cve

CVE-2020-11446

ESET Antivirus and Antispyware Module module 1553 through 1560 allows a user with limited access rights to create hard links in some ESET directories and then force the product to write through these links into files that would normally not be write-able by the user, thus achieving privilege...

7.8CVSS

7.6AI Score

0.0004EPSS

2020-04-29 02:15 PM
26
cve
cve

CVE-2019-12368

The Edison Mail application through 1.7.1 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE...

6.1CVSS

5.9AI Score

0.001EPSS

2020-03-18 07:15 PM
91
cve
cve

CVE-2012-6277

Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss Prevention (DLP) before 11.6.1, IBM Notes.....

7.8CVSS

8.1AI Score

0.004EPSS

2020-02-21 05:15 PM
98
cve
cve

CVE-2019-19265

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for...

6.1CVSS

6AI Score

0.001EPSS

2020-01-06 01:15 AM
77
cve
cve

CVE-2019-19266

IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for...

5.4CVSS

5.2AI Score

0.001EPSS

2020-01-06 12:15 AM
70
cve
cve

CVE-2019-17123

The eGain Web Email API 11+ allows spoofed messages because the fromName and message fields (to /system/ws/v11/ss/email) are mishandled, as demonstrated by fromName header injection with a %0a or %0d character. (Also, the message parameter can have initial HTML comment...

7.5CVSS

7.6AI Score

0.001EPSS

2019-12-13 06:15 PM
45
cve
cve

CVE-2012-5527

Claws Mail vCalendar plugin: credentials exposed on...

5.5CVSS

5.6AI Score

0.0005EPSS

2019-11-25 02:15 PM
21
cve
cve

CVE-2019-12759

Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software...

7.8CVSS

7.9AI Score

0.001EPSS

2019-11-15 06:15 PM
64
cve
cve

CVE-2019-16698

The direct_mail (aka Direct Mail) extension through 5.2.2 for TYPO3 has a missing access check in the backend module, allowing a user (with restricted permissions to the fe_users table) to view and export data of frontend users who are subscribed to a...

4.3CVSS

4.5AI Score

0.001EPSS

2019-10-16 07:15 PM
30
cve
cve

CVE-2016-10956

The mail-masta plugin 1.0 for WordPress has local file inclusion in count_of_send.php and...

7.5CVSS

7.5AI Score

0.011EPSS

2019-09-16 12:15 PM
30
2
cve
cve

CVE-2019-15833

The simple-mail-address-encoder plugin before 1.7 for WordPress has reflected...

6.1CVSS

6.4AI Score

0.001EPSS

2019-08-30 02:15 PM
35
cve
cve

CVE-2019-1084

An information disclosure vulnerability exists when Exchange allows creation of entities with Display Names having non-printable characters. An authenticated attacker could exploit this vulnerability by creating entities with invalid display names, which, when added to conversations, remain...

6.5CVSS

5.3AI Score

0.005EPSS

2019-07-15 07:15 PM
200
cve
cve

CVE-2019-5965

Open redirect vulnerability in Joruri Mail 2.1.4 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified...

6.1CVSS

6.2AI Score

0.001EPSS

2019-07-05 02:15 PM
42
cve
cve

CVE-2019-5966

Joruri Mail 2.1.4 and earlier does not properly manage sessions, which allows remote attackers to impersonate an arbitrary user and alter/disclose the information via unspecified...

5.4CVSS

6AI Score

0.001EPSS

2019-07-05 02:15 PM
150
cve
cve

CVE-2019-12593

IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory...

7.5CVSS

7.3AI Score

0.111EPSS

2019-06-03 05:29 PM
61
cve
cve

CVE-2019-0218

A vulnerability was discovered wherein a specially crafted URL could enable reflected XSS via JavaScript in the pony mail...

6.1CVSS

5.8AI Score

0.004EPSS

2019-04-22 10:29 PM
21
cve
cve

CVE-2019-10741

K-9 Mail v5.600 can include the original quoted HTML code of a specially crafted, benign looking, email within (digitally signed) reply messages. The quoted part can contain conditional statements that show completely different text if opened in a different email client. This can be abused by an...

4.3CVSS

4.7AI Score

0.001EPSS

2019-04-07 03:29 PM
19
cve
cve

CVE-2019-10735

In Claws Mail 3.14.1, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the....

4.3CVSS

4.4AI Score

0.001EPSS

2019-04-07 03:29 PM
24
cve
cve

CVE-2019-9557

Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an...

6.1CVSS

6AI Score

0.001EPSS

2019-03-12 07:29 PM
17
cve
cve

CVE-2017-5658

The statistics generator in Apache Pony Mail 0.7 to 0.9 was found to be returning timestamp data without proper authorization checks. This could lead to derived information disclosure on private lists about the timing of specific email subjects or text bodies, though without disclosing the content....

5.3CVSS

5AI Score

0.001EPSS

2018-10-04 02:29 PM
20
cve
cve

CVE-2018-16324

In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username...

6.1CVSS

6AI Score

0.002EPSS

2018-09-01 06:29 PM
22
cve
cve

CVE-2018-8305

An information disclosure vulnerability exists in Windows Mail Client when a message is opened, aka "Windows Mail Client Information Disclosure Vulnerability." This affects Mail, Calendar, and People in Windows 8.1 App...

6.5CVSS

5.9AI Score

0.019EPSS

2018-07-11 12:29 AM
22
cve
cve

CVE-2018-7475

Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or...

6.1CVSS

6.1AI Score

0.002EPSS

2018-06-30 02:29 PM
19
cve
cve

CVE-2016-9092

The Symantec Content Analysis (CA) 1.3, 2.x prior to 2.2.1.1, and Mail Threat Defense (MTD) 1.1 management consoles are susceptible to a cross-site request forging (CSRF) vulnerability. A remote attacker can use phishing or other social engineering techniques to access the management console with.....

8.8CVSS

8.6AI Score

0.001EPSS

2018-05-17 12:00 AM
21
cve
cve

CVE-2017-17689

The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka...

5.9CVSS

5.6AI Score

0.005EPSS

2018-05-16 07:29 PM
62
cve
cve

CVE-2017-17688

The OpenPGP specification allows a Cipher Feedback Mode (CFB) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL. NOTE: third parties report that this is a problem in applications that mishandle the Modification Detection Code (MDC) feature or accept an...

5.9CVSS

5.7AI Score

0.008EPSS

2018-05-16 07:29 PM
46
cve
cve

CVE-2015-1503

Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter...

7.5CVSS

7.5AI Score

0.904EPSS

2018-05-08 08:29 PM
42
cve
cve

CVE-2018-0514

MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified...

9.8CVSS

9.7AI Score

0.005EPSS

2018-02-08 02:29 PM
22
cve
cve

CVE-2018-6288

Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version...

8.8CVSS

8.9AI Score

0.001EPSS

2018-02-06 03:29 PM
23
cve
cve

CVE-2018-6289

Configuration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version...

9.8CVSS

9.6AI Score

0.005EPSS

2018-02-06 03:29 PM
20
cve
cve

CVE-2018-6291

WebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version...

6.1CVSS

6.4AI Score

0.002EPSS

2018-02-06 03:29 PM
23
cve
cve

CVE-2018-6290

Local Privilege Escalation in Kaspersky Secure Mail Gateway version...

7.8CVSS

8.2AI Score

0.0004EPSS

2018-02-06 03:29 PM
20
cve
cve

CVE-2013-7400

The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication...

7.5CVSS

7.5AI Score

0.003EPSS

2017-12-29 03:29 PM
18
cve
cve

CVE-2017-17752

Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version...

6.1CVSS

5.9AI Score

0.001EPSS

2017-12-20 04:29 PM
33
cve
cve

CVE-2017-15806

The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one...

8.1CVSS

8.1AI Score

0.146EPSS

2017-11-15 04:29 PM
46
cve
cve

CVE-2017-15223

Denial-of-service vulnerability in ArGoSoft Mini Mail Server 1.0.0.2 and earlier allows remote attackers to waste CPU resources (memory consumption) via unspecified vectors, possibly triggering an infinite...

5.3CVSS

5.3AI Score

0.021EPSS

2017-10-24 05:29 PM
35
cve
cve

CVE-2015-5379

Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email...

5.4CVSS

5.3AI Score

0.002EPSS

2017-10-23 06:29 PM
21
cve
cve

CVE-2017-12844

Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user...

4.8CVSS

4.6AI Score

0.001EPSS

2017-08-23 02:29 PM
24
cve
cve

CVE-2016-4460

Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass...

9.8CVSS

9.4AI Score

0.002EPSS

2017-08-22 06:29 PM
21
cve
cve

CVE-2016-4879

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified...

8.8CVSS

8.8AI Score

0.002EPSS

2017-05-12 06:29 PM
21
cve
cve

CVE-2016-4886

Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified...

8.8CVSS

8.8AI Score

0.002EPSS

2017-05-12 06:29 PM
20
cve
cve

CVE-2016-4877

Cross-site scripting vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified...

5.4CVSS

5.2AI Score

0.001EPSS

2017-05-12 06:29 PM
18
cve
cve

CVE-2015-9058

Open redirect vulnerability in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destination...

6.1CVSS

6.3AI Score

0.002EPSS

2017-05-03 10:59 AM
19
cve
cve

CVE-2015-9057

Multiple cross-site scripting (XSS) vulnerabilities in Proxmox Mail Gateway prior to hotfix 4.0-8-097d26a9 allow remote attackers to inject arbitrary web script or HTML via multiple parameters, related to /users/index.htm, /quarantine/spam/manage.htm, /quarantine/spam/whitelist.htm,...

6.1CVSS

6AI Score

0.001EPSS

2017-05-03 10:59 AM
16
cve
cve

CVE-2016-5309

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for...

5.5CVSS

5.1AI Score

0.004EPSS

2017-04-14 06:59 PM
31
20
cve
cve

CVE-2016-5310

The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP); Symantec Email Security.Cloud; Symantec Data Center Security: Server; Symantec Endpoint Protection (SEP) for Windows before 12.1.6 MP5; Symantec Endpoint Protection (SEP) for...

5.5CVSS

5.1AI Score

0.006EPSS

2017-04-14 06:59 PM
26
16
Total number of security vulnerabilities464