Hmailserver is a lightweight email server product with a focused footprint spanning mail transport and messaging functionality. Its observed vulnerability signal centers on cryptographic key management, information disclosure, input validation, and memory-safety issues characteristic of native mail-server implementations. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hmailserver over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-3676MEDIUM Unspecified vulnerability in the IMAP server in hMailServer 4.4.1 allows remote authenticated users to cause a denial of service (resource exhaustion or daemon crash) via a long se | Aug 14, 2008 | 4.3 | 24 | NO | YES |
CVE-2013-5571MEDIUM HMailServer 5.3.x and prior: Memory Corruption which could cause DOS | Jan 7, 2020 | 5.9 | 20 | NO | NO |
CVE-2025-52372MEDIUM An issue in hMailServer v.5.8.6 allows a local attacker to obtain sensitive information via the hmailserver/installation/hMailServerInnoExtension.iss and hMailServer.ini components | Jul 21, 2025 | 5.1 | 17 | NO | NO |
CVE-2025-52373MEDIUM Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config | Jul 21, 2025 | 4.6 | 16 | NO | NO |
CVE-2025-52374MEDIUM Use of hardcoded cryptographic key in Encryption.cs in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords to other servers from hMailAdmin.exe.config file to acc | Jul 21, 2025 | 4.6 | 15 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hmailserver.
Media articles that mention a CVE ID that affects a product developed by Hmailserver — matched by CVE ID, not by vendor name.