Ability Mail Server
Vendor:
First CVE: Dec 31, 2004 · Active for 21 years
7
Total CVEs
More Total CVEs than 49% of tracked products
1.2
Avg CVEs / Year
Bottom 1%
5.4
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ability Mail Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 31, 2004
21 years ago
Most Recent CVE
Mar 12, 2019
2,691 days ago
CVE Severity & Scoring
Ability Mail Server7 CVEs
86%
14%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network2 (28.6%)
Unknown5 (71.4%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (28.6%)
High0 (0.0%)
Unknown5 (71.4%)
User Interaction
None0 (0.0%)
Unknown5 (71.4%)
Required2 (28.6%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None2 (28.6%)
Unknown5 (71.4%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-17752MEDIUM Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is | Dec 20, 2017 | 6.1 | 31 | NO | YES |
CVE-2019-9557MEDIUM Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript | Mar 12, 2019 | 6.1 | 21 | NO | NO |
CVE-2013-6162MEDIUM Cross-site scripting (XSS) vulnerability in Code-Crafters Ability Mail Server 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the body of an email. | Dec 21, 2013 | 4.3 | 21 | NO | YES |
CVE-2004-2494MEDIUM Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter. | Dec 31, 2004 | 4.3 | 21 | NO | YES |
CVE-2004-2495HIGH The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneo | Dec 31, 2004 | 7.8 | 20 | NO | NO |
CVE-2009-3445MEDIUM Unspecified vulnerability in Code-Crafters Ability Mail Server before 2.70 allows remote attackers to cause a denial of service (daemon crash) via an IMAP4 FETCH command. | Sep 28, 2009 | 5.0 | 16 | NO | NO |
CVE-2007-6101MEDIUM Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and | Nov 23, 2007 | 4.0 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
42.9% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Ability Mail Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.2.6 | 1 | 6.1 | 1.0% | 0 | 0 |
| 3.3.2 | 1 | 6.1 | 1.4% | 0 | 1 |
| 3.1.1 | 1 | 4.3 | 1.4% | 0 | 1 |
| 2.62 | 1 | 5.0 | 2.1% | 0 | 0 |
| 2.61 | 1 | 5.0 | 2.1% | 0 | 0 |
| 2.60 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.58 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.57 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.56 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.55 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.54 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.53 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.52 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.51 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.50 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.23 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.22 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.21 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.20 | 2 | 4.5 | 1.8% | 0 | 0 |
| 2.19 | 2 | 4.5 | 1.8% | 0 | 0 |