Merak maintains a focused portfolio centered on mail server and messaging applications that, despite a narrow product scope, occupies a meaningful niche in older enterprise and small-business deployments. The vendor's vulnerability disclosures frequently acquire public exploit code, reflecting the appeal of internet-facing mail infrastructure as a target for both manual and automated attack tooling. Recurring weaknesses span input-validation issues, cross-site scripting in web interfaces, and memory-safety problems in native components, patterns characteristic of legacy mail server codebases with long service lives. Defenders tracking this vendor should prioritize inventory of deployed Merak and IceWarp instances and treat available exploit code as an active remediation driver; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Merak over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0350HIGH Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long string in a .m3u playlist file, related to the status bar icon's | Jan 29, 2009 | 9.3 | 37 | NO | YES |
CVE-2005-4556HIGH PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable | Dec 28, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-4558MEDIUM IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter | Dec 28, 2005 | 6.5 | 29 | NO | YES |
CVE-2004-1722HIGH SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter. | Aug 17, 2004 | 7.5 | 29 | NO | YES |
CVE-2005-4557MEDIUM dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local f | Dec 28, 2005 | 5.0 | 26 | NO | YES |
CVE-2005-4559MEDIUM mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and | Dec 28, 2005 | 5.0 | 25 | NO | YES |
CVE-2004-1720MEDIUM The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals | Aug 17, 2004 | 5.0 | 25 | NO | YES |
CVE-2005-3133MEDIUM Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary | Oct 4, 2005 | 5.0 | 24 | NO | YES |
CVE-2004-1670HIGH Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary direct | Sep 10, 2004 | 7.5 | 24 | NO | NO |
CVE-2002-0258HIGH Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain pri | May 29, 2002 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Merak.
Media articles that mention a CVE ID that affects a product developed by Merak — matched by CVE ID, not by vendor name.