Double Precision Incorporated develops a focused suite of mail infrastructure and messaging products—including Courier Mail Server, Courier IMAP, and SQWebMail—that provide email transmission, retrieval, and web access for Unix and Linux environments. The vendor's disclosures are scattered across disparate weakness classes, reflecting the integration and protocol-handling breadth inherent to mail systems. Current severity, exploitation, and exposure data are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Double Precision Incorporated over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2173HIGH Eval injection vulnerability in (1) courier-imapd.indirect and (2) courier-pop3d.indirect in Courier-IMAP before 4.0.6-r2, and 4.1.x before 4.1.2-r1, on Gentoo Linux allows remote | Apr 24, 2007 | 10.0 | 26 | NO | NO |
CVE-2003-0040HIGH SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name. | Feb 19, 2003 | 7.5 | 24 | NO | NO |
CVE-2004-0224HIGH Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute | Apr 15, 2004 | 7.5 | 21 | NO | NO |
CVE-2006-2659HIGH libs/comverp.c in Courier MTA before 0.53.2 allows attackers to cause a denial of service (CPU consumption) via unknown vectors involving usernames that contain the "=" (equals) ch | May 30, 2006 | 7.8 | 20 | NO | NO |
CVE-2005-3532HIGH authpam.c in courier-authdaemon for Courier Mail Server 0.37.3 through 0.52.1, when using pam_tally, does not call the pam_acct_mgmt function to verify that access should be grante | Dec 11, 2005 | 7.5 | 19 | NO | NO |
CVE-2005-2151MEDIUM spf.c in Courier Mail Server does not properly handle DNS failures when looking up Sender Policy Framework (SPF) records, which could allow attackers to cause memory corruption. | Jul 6, 2005 | 5.0 | 15 | NO | NO |
CVE-2002-0914MEDIUM Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, whi | Oct 4, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-1311MEDIUM Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files. | Nov 29, 2002 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Double Precision Incorporated.
Media articles that mention a CVE ID that affects a product developed by Double Precision Incorporated — matched by CVE ID, not by vendor name.