Isode is a messaging and directory systems vendor with a niche portfolio centered on its M-Link mail transfer agent and M-Vault secure messaging and storage products, which serve specialized enterprise communication requirements. The vendor's durable vulnerability signal reflects its position in critical messaging infrastructure: recurring weaknesses in access control, input validation, memory safety, and credential handling recur across its products and indicate the authentication and protocol-parsing demands of secure communication systems. Public exploit tooling has been associated with this vendor's disclosures; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Isode over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0710HIGH Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code via a crafted LDAP request, as demonstrated by ProtoVer Sampl | Feb 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2022-47634HIGH M-Link Archive Server in Isode M-Link R16.2v1 through R17.0 before R17.0v24 allows non-administrative users to access and manipulate archive data via certain HTTP endpoints, aka LI | Jan 1, 2023 | 8.1 | 26 | NO | NO |
CVE-2022-47581HIGH Isode M-Vault 16.0v0 through 17.x before 17.0v24 can crash upon an LDAP v1 bind request. | Dec 21, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-32389HIGH Isode SWIFT v4.0.2 was discovered to contain hard-coded credentials in the Registry Editor. This allows attackers to access sensitive information such as user credentials and certi | Jul 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2014-2742HIGH Isode M-Link before 16.0v7 does not properly restrict the processing of compressed XML elements, which allows remote attackers to cause a denial of service (resource consumption) v | Apr 11, 2014 | 7.8 | 20 | NO | NO |
CVE-2012-4669MEDIUM M-Link R14.6 before R14.6v14 and R15.1 before R15.1v10 does not verify that a request was made for an XMPP Server Dialback response, which allows remote XMPP servers to spoof domai | Aug 25, 2012 | 5.8 | 19 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Isode.
Media articles that mention a CVE ID that affects a product developed by Isode — matched by CVE ID, not by vendor name.