Mailwise

Vendor:

First CVE: Aug 31, 2006 · Active for 19 years

14
Total CVEs
More Total CVEs than 92% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
5.5
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mailwise over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2006
19 years ago
Most Recent CVE
May 29, 2020
2,250 days ago

CVE Severity & Scoring

Mailwise14 CVEs
All CVEs352,785 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network8 (57.1%)
Unknown5 (35.7%)
Physical1 (7.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (64.3%)
High0 (0.0%)
Unknown5 (35.7%)
User Interaction
None2 (14.3%)
Unknown5 (35.7%)
Required7 (50.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None9 (64.3%)
Unknown5 (35.7%)

Top CVEs

Signals from CVEs in this product scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-m
Nov 24, 20149.029NONO
Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.
Jan 9, 20197.525NONO
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.
Apr 20, 20176.523NONO
Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'Address' via unspecified vectors.
Jun 26, 20186.119NONO
Reflected cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML in 'System settings' via unspecified v
Jun 26, 20186.119NONO
Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified v
Jun 26, 20186.119NONO
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.
Apr 21, 20174.319NONO
Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.
Apr 20, 20174.319NONO
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.
Apr 20, 20174.319NONO
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attack
Apr 25, 20136.818NONO

Exploit Exposure

Signals from CVEs in this product scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (14 CVEs).

Media Mentions

Signals from CVEs in this product scope (14 CVEs).

Top CNAs Publishing CVEs For Mailwise

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.3.244.81.6%00
5.3.144.81.6%00
5.3.044.81.6%00
5.2.144.81.6%00
5.2.044.81.6%00
5.1.444.81.6%00
5.1.244.81.6%00
5.1.144.81.6%00
5.1.044.81.6%00
5.0.644.81.6%00
5.0.554.61.5%00
5.0.454.61.5%00
5.0.144.81.6%00
5.0.044.81.6%00
4.019.03.7%00
3.0\(0.2\)25.41.1%00
3.016.80.6%00
2.125.50.9%00
2.025.50.9%00
1.025.50.9%00