Kerio Mailserver
Vendor:
First CVE: Apr 11, 2003 · Active for 23 years
22
Total CVEs
More Total CVEs than 94% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kerio Mailserver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2003
23 years ago
Most Recent CVE
Mar 22, 2011
5,605 days ago
CVE Severity & Scoring
Kerio Mailserver22 CVEs
9%
59%
32%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown22 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown22 (100.0%)
User Interaction
None0 (0.0%)
Unknown22 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (100.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-0487HIGH Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parame | Aug 7, 2003 | 7.5 | 33 | NO | YES |
CVE-2002-1434MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs. | Apr 11, 2003 | 6.8 | 28 | NO | YES |
CVE-2008-0860HIGH Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs. | Feb 21, 2008 | 10.0 | 27 | NO | NO |
CVE-2007-3993HIGH Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors. | Jul 25, 2007 | 10.0 | 25 | NO | NO |
CVE-2004-2441HIGH Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue." | Dec 31, 2004 | 10.0 | 25 | NO | NO |
CVE-2003-0488MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl mo | Aug 7, 2003 | 5.1 | 25 | NO | YES |
CVE-2011-1506MEDIUM The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert comman | Mar 22, 2011 | 6.8 | 21 | NO | NO |
CVE-2008-0858HIGH Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors. | Feb 21, 2008 | 7.5 | 20 | NO | NO |
CVE-2006-1158HIGH Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command. | Mar 12, 2006 | 7.8 | 20 | NO | NO |
CVE-2005-1062HIGH The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain pa | May 2, 2005 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Kerio Mailserver
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.7.3 | 1 | 6.8 | 2.5% | 0 | 0 |
| 6.7.2 | 1 | 6.8 | 2.5% | 0 | 0 |
| 6.7.1 | 1 | 6.8 | 2.5% | 0 | 0 |
| 6.7.0 | 2 | 5.5 | 1.8% | 0 | 0 |
| 6.6.2 | 2 | 5.5 | 1.8% | 0 | 0 |
| 6.6.1 | 2 | 5.5 | 1.8% | 0 | 0 |
| 6.6.0 | 4 | 5.0 | 1.6% | 0 | 0 |
| 6.5.2 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.5.1 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.5.0 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.4.2 | 4 | 5.1 | 1.6% | 0 | 0 |
| 6.4.1 | 4 | 5.1 | 1.6% | 0 | 0 |
| 6.4.0 | 4 | 5.1 | 1.6% | 0 | 0 |
| 6.3.1_p2 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.3.1_p1 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.3.1 | 4 | 5.1 | 1.6% | 0 | 0 |
| 6.3.0 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.2.2 | 4 | 5.1 | 1.6% | 0 | 0 |
| 6.2.1 | 3 | 5.1 | 1.6% | 0 | 0 |
| 6.2.0 | 3 | 5.1 | 1.6% | 0 | 0 |