Daj develops a focused line of email and content-filtering products, notably the i-Filter suite and DSPA appliance line, that sit at the gateway between organizations and the internet. Its vulnerability exposure centers on recurrent weaknesses in trust assumptions, authentication handling, and input validation—including untrusted search paths, improper authentication mechanisms, certificate validation gaps, HTTP header injection, and cross-site scripting—that are characteristic of gateway-inspection and web-facing software. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Daj over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-10859HIGH Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to gain privileges via a Trojan horse DLL i | Sep 15, 2017 | 7.8 | 24 | NO | NO |
CVE-2017-10858HIGH Untrusted search path vulnerability in "i-filter 6.0 install program" file version 1.0.8.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecifie | Sep 15, 2017 | 7.8 | 24 | NO | NO |
CVE-2023-22278MEDIUM m-FILTER prior to Ver.5.70R01 (Ver.5 Series) and m-FILTER prior to Ver.4.87R04 (Ver.4 Series) allows a remote unauthenticated attacker to bypass authentication and send users' unin | Jan 17, 2023 | 5.3 | 20 | NO | NO |
CVE-2018-16180MEDIUM Cross-site scripting vulnerability in i-FILTER Ver.9.50R05 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Jan 9, 2019 | 6.1 | 20 | NO | NO |
CVE-2017-10860HIGH Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to execute arbitrary code via a specially c | Sep 15, 2017 | 7.8 | 20 | NO | NO |
CVE-2018-16181MEDIUM HTTP header injection vulnerability in i-FILTER Ver.9.50R05 and earlier may allow remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks that | Jan 9, 2019 | 6.1 | 19 | NO | NO |
Improper check for certificate revocation in i-FILTER Ver.10.45R01 and earlier, i-FILTER Ver.9.50R10 and earlier, i-FILTER Browser & Cloud MultiAgent for Windows Ver.4.93R04 and ea | Mar 10, 2022 | 3.7 | 13 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Daj.
Media articles that mention a CVE ID that affects a product developed by Daj — matched by CVE ID, not by vendor name.