Emumail is a niche webmail platform with a narrow product portfolio spanning variants across Unix and Linux environments, presenting a focused attack surface rather than a broad landscape presence. The vendor's vulnerabilities are characterized by a strong tendency toward public exploit availability, which underscores the importance of timely patching for organizations still running these systems. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Emumail over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2004-2334MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable p | Dec 31, 2004 | 4.3 | 27 | NO | YES |
CVE-2004-2385MEDIUM EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. | Dec 31, 2004 | 5.0 | 25 | NO | YES |
CVE-2002-1527MEDIUM emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression | Apr 2, 2003 | 5.0 | 25 | NO | YES |
CVE-2002-1526MEDIUM Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field. | Apr 2, 2003 | 4.3 | 22 | NO | YES |
CVE-2002-0532HIGH EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot sp | Aug 12, 2002 | 7.2 | 18 | NO | NO |
CVE-2002-0531MEDIUM Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in | Aug 12, 2002 | 5.0 | 16 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Emumail.
Media articles that mention a CVE ID that affects a product developed by Emumail — matched by CVE ID, not by vendor name.