Dbmail is a mail-storage system with a focused product footprint centered on its core mail server, where the durable exposure signal reflects authentication handling and SQL query construction within the database-backed message store. The recurring weakness classes—improper authentication and SQL injection—are characteristic of database-driven mail systems and should inform defensive configuration and access-control reviews. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dbmail over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1523HIGH SQL injection vulnerability in the IMAP daemon in dbmail 1.1 allows remote attackers to execute arbitrary SQL commands via the (1) login username, (2) mailbox name, and possibly ot | Dec 31, 2003 | 7.5 | 24 | NO | NO |
CVE-2007-6714MEDIUM DBMail before 2.2.9, when using authldap with an LDAP server that supports anonymous login such as Active Directory, allows remote attackers to bypass authentication via an empty p | Apr 17, 2008 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dbmail.
Media articles that mention a CVE ID that affects a product developed by Dbmail — matched by CVE ID, not by vendor name.