Inter7 develops a narrowly focused suite of mail-server and management tools including Courier IMAP, Sqwebmail, and related components that serve smaller hosting and mail-infrastructure deployments. The recurring weakness classes center on format-string vulnerabilities and input-handling issues characteristic of legacy C-based mail software, and the vendor's disclosures frequently acquire public exploit code. Defenders managing Inter7-based mail infrastructure should prioritize patches for these components and monitor for exploitation activity; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Inter7 over time
Signals from CVEs in this vendor scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2000-0091HIGH Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password. | Jan 21, 2000 | 10.0 | 41 | NO | YES |
CVE-2004-0777HIGH Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attac | Oct 20, 2004 | 7.5 | 33 | NO | YES |
CVE-2007-0558HIGH PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR paramet | Jan 30, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-1308HIGH SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML. | Apr 15, 2005 | 7.5 | 28 | NO | YES |
CVE-2004-0591MEDIUM Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script o | Aug 6, 2004 | 6.8 | 28 | NO | YES |
CVE-2004-2239HIGH Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code. | Dec 31, 2004 | 7.5 | 25 | NO | NO |
CVE-2003-0040HIGH SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name. | Feb 19, 2003 | 7.5 | 24 | NO | NO |
CVE-2006-1141HIGH Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable. | Mar 10, 2006 | 7.5 | 21 | NO | NO |
CVE-2005-2769MEDIUM Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing | Sep 2, 2005 | 4.3 | 21 | NO | YES |
CVE-2004-0224HIGH Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute | Apr 15, 2004 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (18 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Inter7.
Media articles that mention a CVE ID that affects a product developed by Inter7 — matched by CVE ID, not by vendor name.