Web Mail

Vendor:

First CVE: May 29, 2002 · Active for 24 years

25
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Web Mail over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2002
24 years ago
Most Recent CVE
Jul 21, 2006
7,309 days ago

CVE Severity & Scoring

Web Mail25 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown25 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown25 (100.0%)
User Interaction
None0 (0.0%)
Unknown25 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown25 (100.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable
Dec 28, 20057.532NOYES
IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter
Dec 28, 20056.529NOYES
Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) usern
Jan 28, 20055.028NOYES
dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local f
Dec 28, 20055.026NOYES
mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and
Dec 28, 20055.025NOYES
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary
Oct 4, 20055.024NOYES
Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary direct
Sep 10, 20047.524NONO
Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain pri
May 29, 20027.524NONO
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitra
Oct 4, 20054.322NOYES
attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the userna
Oct 12, 20047.519NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
28.0% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Web Mail

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.6.024.53.8%00
5.5.185.36.1%06
5.4.243.40.7%00
5.414.31.2%00
5.3.225.80.7%00
5.3.114.31.2%00
5.3.024.70.5%00
5.324.71.9%01
5.2.876.21.6%00
5.2.776.21.6%00
4.1.514.31.2%00
4.1.414.31.2%00
3.5.114.31.2%00
3.5.014.31.2%00
3.4.214.31.2%00
3.4.114.31.2%00
3.3.514.31.3%00
3.3.314.31.3%00
3.3.276.21.6%00
3.3.114.31.2%00