Deerfield develops a portfolio of email, web, and file-transfer server products including Visnetic Mail Server, MDaemon, and Serv-U that operate in communication and data-exchange infrastructure roles. The vendor's vulnerability disclosures recur through weakness classes centered on information exposure and input-handling defects such as cross-site scripting, reflecting the web-facing and parsing demands of email and file-transfer systems, and frequently acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Deerfield over time
Signals from CVEs in this vendor scope (15 CVEs).
15 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4556HIGH PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable | Dec 28, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-4558MEDIUM IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter | Dec 28, 2005 | 6.5 | 29 | NO | YES |
CVE-2005-4557MEDIUM dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local f | Dec 28, 2005 | 5.0 | 26 | NO | YES |
CVE-2005-4559MEDIUM mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and | Dec 28, 2005 | 5.0 | 25 | NO | YES |
CVE-1999-0844MEDIUM Denial of service in MDaemon WorldClient and WebConfig services via a long URL. | Nov 24, 1999 | 5.0 | 24 | NO | YES |
CVE-1999-0838MEDIUM Buffer overflow in Serv-U FTP 2.5 allows remote users to conduct a denial of service via the SITE command. | Dec 1, 1999 | 5.0 | 23 | NO | YES |
CVE-2002-2246MEDIUM Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary web script or HTML via the HTTP referer header (HTTP_REFERER) | Dec 31, 2002 | 4.3 | 21 | NO | YES |
CVE-2002-2413MEDIUM WebSite Pro 3.1.11.0 on Windows allows remote attackers to read script source code for files with extensions greater than 3 characters via a URL request that uses the equivalent 8. | Dec 31, 2002 | 5.0 | 19 | NO | NO |
CVE-2006-0817MEDIUM Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer before 8.5.0.5 allows rem | Jul 21, 2006 | 5.0 | 16 | NO | NO |
CVE-2003-0456MEDIUM VisNetic WebSite 3.5 allows remote attackers to obtain the full pathname of the server via a request containing a folder that does not exist, which leaks the pathname in an error m | Aug 18, 2003 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (15 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Deerfield.
Media articles that mention a CVE ID that affects a product developed by Deerfield — matched by CVE ID, not by vendor name.