Alt N maintains a focused portfolio of email and messaging infrastructure products, including MDaemon, WebAdmin, WorldClient, and SecurityGateway, that serve as backbone systems for business communication and security filtering. Despite a narrow product range, these solutions occupy a prominent position in enterprise messaging deployments, particularly among organizations running on-premises mail infrastructure. Vulnerabilities affecting this vendor have historically centered on the complexity inherent to email processing, message parsing, and authentication handling in mission-critical systems where availability and data integrity are paramount. Defenders should inventory instances of these products within their messaging architecture and apply vendor updates prioritarily; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Alt N over time
Signals from CVEs in this vendor scope (65 CVEs).
65 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-4193HIGH Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers to execute arbitrary code via a long username parameter. | Sep 24, 2008 | 10.0 | 81 | NO | YES |
CVE-2003-1200HIGH Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi. | Dec 29, 2003 | 7.5 | 72 | NO | YES |
CVE-2003-0471HIGH Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to WebAdmin.dll with a long USER argument. | Aug 7, 2003 | 7.5 | 70 | NO | YES |
CVE-2008-1358MEDIUM Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY. | Mar 17, 2008 | 6.5 | 67 | NO | YES |
CVE-2006-4364MEDIUM Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly e | Aug 27, 2006 | 5.0 | 52 | NO | YES |
CVE-2004-1546MEDIUM Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP serv | Dec 31, 2004 | 5.0 | 37 | NO | YES |
CVE-2022-25356MEDIUM Alt-N MDaemon Security Gateway through 8.5.0 allows SecurityGateway.dll?view=login XML Injection. | Apr 5, 2022 | 5.3 | 32 | NO | YES |
CVE-2008-2631MEDIUM The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTT | Jun 10, 2008 | 5.0 | 32 | NO | YES |
CVE-2000-1021HIGH Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. | Dec 11, 2000 | 7.5 | 32 | NO | YES |
CVE-2020-18724MEDIUM Authenticated stored cross-site scripting (XSS) in the contact name field in the distribution list of MDaemon webmail 19.5.5 allows an attacker to executes code and perform a XSS a | Feb 3, 2021 | 5.4 | 30 | NO | YES |
Signals from CVEs in this vendor scope (65 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Alt N.
Media articles that mention a CVE ID that affects a product developed by Alt N — matched by CVE ID, not by vendor name.