Mail Server
Vendor:
First CVE: May 29, 2002 · Active for 24 years
23
Total CVEs
More Total CVEs than 95% of tracked products
5.8
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
5.2
Avg CVSS
Higher Avg CVSS than 9% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Mail Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 29, 2002
24 years ago
Most Recent CVE
Jul 21, 2006
7,308 days ago
CVE Severity & Scoring
Mail Server23 CVEs
13%
61%
26%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown23 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown23 (100.0%)
User Interaction
None0 (0.0%)
Unknown23 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown23 (100.0%)
Top CVEs
Signals from CVEs in this product scope (23 CVEs).
23 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4556HIGH PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when register_globals is enable | Dec 28, 2005 | 7.5 | 32 | NO | YES |
CVE-2005-4558MEDIUM IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for the language parameter | Dec 28, 2005 | 6.5 | 29 | NO | YES |
CVE-2004-1722HIGH SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter. | Aug 17, 2004 | 7.5 | 29 | NO | YES |
CVE-2005-4557MEDIUM dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to include arbitrary local f | Dec 28, 2005 | 5.0 | 26 | NO | YES |
CVE-2005-4559MEDIUM mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize the default_layout and | Dec 28, 2005 | 5.0 | 25 | NO | YES |
CVE-2004-1720MEDIUM The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP request, which reveals | Aug 17, 2004 | 5.0 | 25 | NO | YES |
CVE-2005-3133MEDIUM Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to (1) delete arbitrary | Oct 4, 2005 | 5.0 | 24 | NO | YES |
CVE-2004-1670HIGH Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) create arbitrary direct | Sep 10, 2004 | 7.5 | 24 | NO | NO |
CVE-2002-0258HIGH Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access to the ID to gain pri | May 29, 2002 | 7.5 | 24 | NO | NO |
CVE-2005-3131MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attackers to inject arbitra | Oct 4, 2005 | 4.3 | 22 | NO | YES |
Exploit Exposure
Signals from CVEs in this product scope (23 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
9 CVEs
39.1% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (23 CVEs).
Media Mentions
Signals from CVEs in this product scope (23 CVEs).
Top CNAs Publishing CVEs For Mail Server
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.3.8r | 2 | 4.5 | 3.8% | 0 | 0 |
| 8.3.0r | 4 | 6.0 | 9.2% | 0 | 4 |
| 8.2.4r | 3 | 4.8 | 3.7% | 0 | 2 |
| 8.0.3 | 4 | 3.4 | 0.7% | 0 | 0 |
| 7.6.4r | 1 | 7.2 | 0.2% | 0 | 0 |
| 7.6.0 | 2 | 4.7 | 0.5% | 0 | 0 |
| 7.5.2 | 1 | 7.5 | 2.7% | 0 | 1 |
| 7.4.5 | 5 | 5.7 | 3.5% | 0 | 2 |
| 5.2.7 | 1 | 5.0 | 2.4% | 0 | 0 |