Imp maintains a narrow product portfolio centered on mail and webmail applications. The observed vulnerability exposure involves generic or miscellaneous weakness classes that do not form a clear structural pattern. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Imp over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0857HIGH Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies | Dec 6, 2001 | 7.5 | 37 | NO | YES |
CVE-2000-0459MEDIUM IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large num | Apr 22, 2000 | 5.0 | 15 | NO | NO |
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information. | Apr 22, 2000 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Imp.
Media articles that mention a CVE ID that affects a product developed by Imp — matched by CVE ID, not by vendor name.