Incredimail develops email client software and related shell extensions, with a small vulnerability footprint centered around memory-safety issues in its core application and ActiveX control components. The observed weakness classes reflect the memory-handling challenges inherent to legacy desktop email clients; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Incredimail over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1683MEDIUM Stack-based buffer overflow in the DoWebMenuAction function in the IncrediMail IMMenuShellExt ActiveX control (ImShExt.dll) allows remote attackers to execute arbitrary code via un | Apr 26, 2007 | 6.8 | 46 | NO | YES |
CVE-2010-5289HIGH Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2.0 allows remote attackers to cause a denial of service (app | Aug 25, 2013 | 7.5 | 32 | NO | YES |
CVE-2002-0455MEDIUM IncrediMail stores attachments in a directory with a fixed name, which could make it easier for attackers to exploit vulnerabilities in other software that rely on installing and r | Aug 12, 2002 | 5.0 | 19 | NO | NO |
CVE-2008-5429MEDIUM Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822 | Dec 11, 2008 | 4.3 | 14 | NO | NO |
Directory traversal vulnerability in IncrediMail version 1400185 and earlier allows local users to overwrite files on the local hard drive by appending .. (dot dot) sequences to fi | Sep 20, 2001 | 2.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Incredimail.
Media articles that mention a CVE ID that affects a product developed by Incredimail — matched by CVE ID, not by vendor name.