Neo's vulnerability footprint concentrates in a narrow portfolio of messaging and collaboration products, specifically its Debun POP and IMAP implementations, which handle sensitive email and authentication workflows. The vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur across memory-safety issues including buffer overflows, hard-coded credential exposure, and input-handling flaws such as cross-site scripting and SQL injection that are characteristic of email protocol parsers. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Neo over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-0683CRITICAL Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code | Nov 15, 2018 | 9.8 | 33 | NO | NO |
CVE-2018-0684CRITICAL Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code | Nov 15, 2018 | 9.8 | 32 | NO | NO |
CVE-2018-0682CRITICAL Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) does not properly manage sessions, which allows remote attackers to | Nov 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-0680CRITICAL Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to rea | Nov 15, 2018 | 9.8 | 31 | NO | NO |
CVE-2018-0681CRITICAL Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to log | Nov 15, 2018 | 9.8 | 30 | NO | NO |
CVE-2018-0686HIGH Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote authenticated attackers to upload and execute any exec | Nov 15, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-0685HIGH SQL injection vulnerability in the Denbun POP version V3.3P R4.0 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via HTTP requests for mail sear | Nov 15, 2018 | 8.8 | 28 | NO | NO |
CVE-2018-0687MEDIUM Cross-site scripting vulnerability in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to inj | Nov 15, 2018 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Neo.
Media articles that mention a CVE ID that affects a product developed by Neo — matched by CVE ID, not by vendor name.