E Post Corporation maintains a narrowly focused email and messaging platform portfolio centered on products such as SPA Pro Mail at Solomon and its mail server and SMTP infrastructure components. The vendor's vulnerability exposure reflects the input-handling and protocol-parsing demands inherent to email systems, though the specific weakness patterns remain diffuse across the product line. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by E Post Corporation over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0447HIGH Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2 | Jan 27, 2006 | 7.5 | 21 | NO | NO |
CVE-2006-0448HIGH Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a | Jan 27, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0449MEDIUM Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APP | Jan 27, 2006 | 5.0 | 15 | NO | NO |
CVE-2008-2049MEDIUM The POP3 server (EPSTPOP3S.EXE) 4.22 in E-Post Mail Server 4.10 allows remote attackers to obtain sensitive information via multiple crafted APOP commands for a known POP3 account, | May 1, 2008 | 4.3 | 14 | NO | NO |
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary | Jun 9, 2005 | 3.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by E Post Corporation.
Media articles that mention a CVE ID that affects a product developed by E Post Corporation — matched by CVE ID, not by vendor name.