Endymion's vulnerability footprint centers on a narrow set of webmail and mail-server products, presenting a focused but specialized exposure in the email infrastructure landscape. The observed weakness classes associated with these products reflect miscellaneous or unclassified issues; current severity, exploitation, and exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Endymion over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0021HIGH MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the alternate_template parameter. | Feb 16, 2001 | 10.0 | 41 | NO | YES |
CVE-2002-0417MEDIUM Directory traversal vulnerability in Endymion MailMan before 3.1 allows remote attackers to read arbitrary files via a .. (dot dot) and a null character in the ALTERNATE_TEMPLATES | Aug 12, 2002 | 5.0 | 15 | NO | NO |
CVE-2002-0418MEDIUM Directory traversal vulnerability in the com.endymion.sake.servlet.mail.MailServlet servlet for Endymion SakeMail 1.0.36 and earlier allows remote attackers to read arbitrary files | Aug 12, 2002 | 5.0 | 15 | NO | NO |
The default permissions for Endymion MailMan allow local users to read email or modify files. | Dec 2, 1999 | 3.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Endymion.
Media articles that mention a CVE ID that affects a product developed by Endymion — matched by CVE ID, not by vendor name.