Microworld Technologies develops a focused line of email security and antivirus products, including MailScan and eScan variants, that recur across small-to-medium business deployments. Its vulnerability profile clusters around input-handling and authentication weaknesses such as path traversal, cross-site scripting, and improper authentication that are characteristic of legacy security software, and these issues frequently acquire public exploit code. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Microworld Technologies over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-2687HIGH Stack-based buffer overflow in the MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan before 9.0.718.1 allows remote attackers to execute arbitrary code via a | May 24, 2007 | 10.0 | 28 | NO | NO |
CVE-2007-0655HIGH The MicroWorld Agent service (MWAGENT.EXE) in MicroWorld Technologies eScan 8.0.671.1, and possibly other versions, allows remote or local attackers to gain privileges and execute | May 2, 2007 | 10.0 | 28 | NO | NO |
CVE-2007-4649HIGH MicroWorld eScan Virus Control 9.0.722.1, Anti-Virus 9.0.722.1, and Internet Security 9.0.722.1 use weak permissions (Everyone:Full Control) for their installation directory trees, | Aug 31, 2007 | 7.2 | 27 | NO | YES |
CVE-2008-1221MEDIUM Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Management Console (aka eScan Server) 9.0.742.1 allows remote att | Mar 10, 2008 | 5.0 | 23 | NO | YES |
CVE-2008-3729HIGH Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to bypass authentication and obtain administrative access via a direct request | Aug 20, 2008 | 7.5 | 19 | NO | NO |
CVE-2008-3727MEDIUM Directory traversal vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to read arbitrary files via a .. (dot dot) | Aug 20, 2008 | 5.0 | 16 | NO | NO |
CVE-2008-3728MEDIUM Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 stores sensitive information under the web root with insufficient access control, which allows remote a | Aug 20, 2008 | 5.0 | 15 | NO | NO |
CVE-2008-3726MEDIUM Cross-site scripting (XSS) vulnerability in Web Based Administration in MicroWorld Technologies MailScan 5.6.a espatch 1 allows remote attackers to inject arbitrary web script or H | Aug 20, 2008 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Microworld Technologies.
Media articles that mention a CVE ID that affects a product developed by Microworld Technologies — matched by CVE ID, not by vendor name.