Web Mail
Vendor:
First CVE: May 29, 2002 · Active for 24 years
25
Total CVEs
More Total CVEs than 95% of tracked products
6.3
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Web Mail over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2002
24 years ago
Most Recent CVE
Jul 21, 2006
7,309 days ago
CVE Severity & Scoring
Web Mail25 CVEs
12%
60%
28%
All CVEs352,708 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown25 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown25 (100.0%)
User Interaction
None0 (0.0%)
Unknown25 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown25 (100.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4556HIGH PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable | Dec 28, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-4558MEDIUM IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter | Dec 28, 2005 | 6.5 | 29 | NO | YES |
CVE-2005-0320MEDIUM Multiple cross-site scripting vulnerabilities in MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) usern | Jan 28, 2005 | 5.0 | 28 | NO | YES |
CVE-2005-4557MEDIUM dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local f | Dec 28, 2005 | 5.0 | 26 | NO | YES |
CVE-2005-4559MEDIUM mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and | Dec 28, 2005 | 5.0 | 25 | NO | YES |
CVE-2005-3133MEDIUM Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary | Oct 4, 2005 | 5.0 | 24 | NO | YES |
CVE-2004-1670HIGH Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary direct | Sep 10, 2004 | 7.5 | 24 | NO | NO |
CVE-2002-0258HIGH Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain pri | May 29, 2002 | 7.5 | 24 | NO | NO |
CVE-2005-3131MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitra | Oct 4, 2005 | 4.3 | 22 | NO | YES |
CVE-2004-1672HIGH attachment.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to view other users' attachments by specifying the userna | Oct 12, 2004 | 7.5 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
28.0% of CVEs· 90th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Web Mail
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.6.0 | 2 | 4.5 | 3.8% | 0 | 0 |
| 5.5.1 | 8 | 5.3 | 6.1% | 0 | 6 |
| 5.4.2 | 4 | 3.4 | 0.7% | 0 | 0 |
| 5.4 | 1 | 4.3 | 1.2% | 0 | 0 |
| 5.3.2 | 2 | 5.8 | 0.7% | 0 | 0 |
| 5.3.1 | 1 | 4.3 | 1.2% | 0 | 0 |
| 5.3.0 | 2 | 4.7 | 0.5% | 0 | 0 |
| 5.3 | 2 | 4.7 | 1.9% | 0 | 1 |
| 5.2.8 | 7 | 6.2 | 1.6% | 0 | 0 |
| 5.2.7 | 7 | 6.2 | 1.6% | 0 | 0 |
| 4.1.5 | 1 | 4.3 | 1.2% | 0 | 0 |
| 4.1.4 | 1 | 4.3 | 1.2% | 0 | 0 |
| 3.5.1 | 1 | 4.3 | 1.2% | 0 | 0 |
| 3.5.0 | 1 | 4.3 | 1.2% | 0 | 0 |
| 3.4.2 | 1 | 4.3 | 1.2% | 0 | 0 |
| 3.4.1 | 1 | 4.3 | 1.2% | 0 | 0 |
| 3.3.5 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.3.3 | 1 | 4.3 | 1.3% | 0 | 0 |
| 3.3.2 | 7 | 6.2 | 1.6% | 0 | 0 |
| 3.3.1 | 1 | 4.3 | 1.2% | 0 | 0 |