Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Extremail

First CVE: Jun 21, 2001Active for: 25 yearsTotal CVEs: 7

Extremail is a narrowly scoped email platform with a niche footprint, yet its recurring disclosures around memory-buffer boundary violations and related memory-safety issues reflect the parsing and state-management demands of email processing systems. Public exploit tooling has been developed for vulnerabilities affecting this vendor, making timely patching of Extremail deployments a practical security priority despite the modest disclosure volume. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
2.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
10.0
Avg CVSS Score
Higher Avg CVSS Score than 99% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Extremail over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 21, 2001
25 years ago
Most Recent CVE
Oct 15, 2007
6,857 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2007-5466HIGH
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending multiple long strings to the IMAP port (143/tcp); (2) execu
Oct 15, 200710.045NOYES
CVE-2001-1078HIGH
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2)
Jun 21, 200110.043NOYES
CVE-2007-5467HIGH
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via a long USER command containing "%s" s
Oct 15, 200710.041NOYES
CVE-2007-2187HIGH
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long DNS response. NOTE: this might be related to CVE-2006-6926.
Apr 24, 200710.037NOYES
CVE-2007-2188HIGH
eXtremail 2.1.1 and earlier does not verify the ID field (aka transaction id) in DNS responses, which makes it easier for remote attackers to conduct DNS spoofing.
Apr 24, 200710.026NONO
CVE-2004-0332HIGH
Extremail 1.5.9 does not check passwords correctly when they are all digits or begin with a digit, which allows remote attackers to gain privileges.
Nov 23, 200410.025NONO
CVE-2006-6926HIGH
Buffer overflow in eXtremail 2.1 has unknown impact and attack vectors, as demonstrated by VulnDisco Pack. NOTE: The provenance of this information is unknown; the details are obt
Jan 13, 200710.024NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
100%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
High
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown7 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown7 (100.0%)
User Interaction
None0 (0.0%)
Unknown7 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown7 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
57.1% of CVEs· 83rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Extremail.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Extremail — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Extremail's Products

View all 1 CNAs →

Top CWEs