Calacode maintains a focused webmail platform, Atmail, that serves as a niche email and collaboration system embedded in hosting and communications environments. Its vulnerability profile centers on application-layer input-handling and authentication weaknesses, including cross-site scripting and improper authentication mechanisms, that are typical of web-facing communication systems. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Calacode over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3579HIGH Calacode @Mail 5.41 on Linux does not require administrative authentication for build-plesk-upgrade.php, which allows remote attackers to obtain sensitive information by creating a | Aug 10, 2008 | 7.8 | 20 | NO | NO |
CVE-2006-6700MEDIUM Cross-site scripting (XSS) vulnerability in @Mail WebMail allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This information is based u | Dec 23, 2006 | 6.8 | 19 | NO | NO |
CVE-2004-2379MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in @Mail 3.64 for Windows allow remote attackers to inject arbitrary web script or HTML via (1) the Displayed Name attribute in | Dec 31, 2004 | 4.3 | 17 | NO | NO |
CVE-2008-3395MEDIUM Calacode @Mail 5.41 on Linux uses weak world-readable permissions for (1) webmail/libs/Atmail/Config.php and (2) webmail/webadmin/.htpasswd, which allows local users to obtain sens | Jul 31, 2008 | 5.0 | 15 | NO | NO |
CVE-2006-0842MEDIUM Cross-site scripting (XSS) vulnerability in Calacode @Mail 4.3 allows remote attackers to inject arbitrary web script or HTML via a modified javascript: string in the SRC attribute | Feb 22, 2006 | 4.3 | 15 | NO | NO |
CVE-2004-2378MEDIUM @Mail 3.64 for Windows allows remote attackers to cause a denial of service ("unusable" server) via a large number of POP3 connections to the server. | Dec 31, 2004 | 5.0 | 15 | NO | NO |
CVE-2007-6196MEDIUM Cross-site scripting (XSS) vulnerability in util.php in Calacode @Mail before 5.2 allows remote attackers to inject arbitrary web script or HTML via the func parameter. | Dec 1, 2007 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Calacode.
Media articles that mention a CVE ID that affects a product developed by Calacode — matched by CVE ID, not by vendor name.