Kerio Mailserver

Vendor:

First CVE: Apr 11, 2003 · Active for 23 years

22
Total CVEs
More Total CVEs than 94% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Kerio Mailserver over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 11, 2003
23 years ago
Most Recent CVE
Mar 22, 2011
5,605 days ago

CVE Severity & Scoring

Kerio Mailserver22 CVEs
All CVEs352,719 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown22 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown22 (100.0%)
User Interaction
None0 (0.0%)
Unknown22 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown22 (100.0%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via (1) a long showuser parame
Aug 7, 20037.533NOYES
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
Apr 11, 20036.828NOYES
Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote attack vectors related to null DACLs.
Feb 21, 200810.027NONO
Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote attack vectors.
Jul 25, 200710.025NONO
Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors, related to a "potential security issue."
Dec 31, 200410.025NONO
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary web script via (1) the add_name parameter in the add_acl mo
Aug 7, 20035.125NOYES
The STARTTLS implementation in Kerio Connect 7.1.4 build 2985 and MailServer 6.x does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert comman
Mar 22, 20116.821NONO
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.
Feb 21, 20087.520NONO
Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a crafted IMAP LOGIN command.
Mar 12, 20067.820NONO
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain pa
May 2, 20057.520NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
13.6% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Kerio Mailserver

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
6.7.316.82.5%00
6.7.216.82.5%00
6.7.116.82.5%00
6.7.025.51.8%00
6.6.225.51.8%00
6.6.125.51.8%00
6.6.045.01.6%00
6.5.235.11.6%00
6.5.135.11.6%00
6.5.035.11.6%00
6.4.245.11.6%00
6.4.145.11.6%00
6.4.045.11.6%00
6.3.1_p235.11.6%00
6.3.1_p135.11.6%00
6.3.145.11.6%00
6.3.035.11.6%00
6.2.245.11.6%00
6.2.135.11.6%00
6.2.035.11.6%00