Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Inter7

First CVE: Jan 21, 2000Active for: 27 yearsTotal CVEs: 18
41.7
VTI Score
High

Inter7 develops a narrowly focused suite of mail-server and management tools including Courier IMAP, Sqwebmail, and related components that serve smaller hosting and mail-infrastructure deployments. The recurring weakness classes center on format-string vulnerabilities and input-handling issues characteristic of legacy C-based mail software, and the vendor's disclosures frequently acquire public exploit code. Defenders managing Inter7-based mail infrastructure should prioritize patches for these components and monitor for exploitation activity; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Inter7 over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 21, 2000
26 years ago
Most Recent CVE
Jan 30, 2007
7,115 days ago

Products(7 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2000-0091HIGH
Buffer overflow in vchkpw/vpopmail POP authentication package allows remote attackers to gain root privileges via a long username or password.
Jan 21, 200010.041NOYES
CVE-2004-0777HIGH
Format string vulnerability in the auth_debug function in Courier-IMAP 1.6.0 through 2.2.1 and 3.x through 3.0.3, when login debugging (DEBUG_LOGIN) is enabled, allows remote attac
Oct 20, 20047.533NOYES
CVE-2007-0558HIGH
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the MODULES_DIR paramet
Jan 30, 20077.528NOYES
CVE-2005-1308HIGH
SqWebMail allows remote attackers to inject arbitrary web script or HTML via CRLF sequences in the redirect parameter followed by the desired script or HTML.
Apr 15, 20057.528NOYES
CVE-2004-0591MEDIUM
Cross-site scripting (XSS) vulnerability in the print_header_uc function for SqWebMail 4.0.4 and earlier, and possibly 3.x, allows remote attackers to inject arbitrary web script o
Aug 6, 20046.828NOYES
CVE-2004-2239HIGH
Buffer overflow in vsybase.c in vpopmail 5.4.2 and earlier might allow attackers to cause a denial of service or execute arbitrary code.
Dec 31, 20047.525NONO
CVE-2003-0040HIGH
SQL injection vulnerability in the PostgreSQL auth module for courier 0.40 and earlier allows remote attackers to execute SQL code via the user name.
Feb 19, 20037.524NONO
CVE-2006-1141HIGH
Buffer overflow in qmailadmin.c in QmailAdmin before 1.2.10 allows remote attackers to execute arbitrary code via a long PATH_INFO environment variable.
Mar 10, 20067.521NONO
CVE-2005-2769MEDIUM
Cross-site scripting (XSS) vulnerability in SqWebMail 5.0.4 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail containing
Sep 2, 20054.321NOYES
CVE-2004-0224HIGH
Multiple buffer overflows in (1) iso2022jp.c or (2) shiftjis.c for Courier-IMAP before 3.0.0, Courier before 0.45, and SqWebMail before 4.0.0 may allow remote attackers to execute
Apr 15, 20047.521NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
50%
50%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown18 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown18 (100.0%)
User Interaction
None0 (0.0%)
Unknown18 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown18 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
38.9% of CVEs· 80th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Inter7.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Inter7 — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Inter7's Products

View all 1 CNAs →

Top CWEs