Roaring Penguin develops a focused portfolio of email security and network access products, including MIME Defang, PPPoE, CanIt, and Remind, that operate at infrastructure chokepoints where parsing and protocol handling create narrow but consequential attack surfaces. The vendor's vulnerabilities recur through memory-safety issues characteristic of legacy C-based infrastructure software, and its disclosures have an elevated tendency to acquire public exploit code. Defenders tracking this vendor should prioritize memory-safety patches for mail and access-control layers; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Roaring Penguin over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-0026MEDIUM rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet with a zero-length TCP option. | Feb 12, 2001 | 5.0 | 31 | NO | YES |
CVE-2015-5957HIGH Buffer overflow in the DumpSysVar function in var.c in Remind before 3.1.15 allows attackers to have unspecified impact via a long name. | Sep 28, 2015 | 10.0 | 25 | NO | NO |
CVE-2004-1098HIGH MIMEDefang in MIME-tools 5.414 allows remote attackers to bypass virus scanning capabilities via an e-mail attachment with a virus that contains an empty boundary string in the Con | Jan 10, 2005 | 7.5 | 24 | NO | NO |
CVE-2002-1121HIGH SMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the default configuration of MIMEDefan | Sep 24, 2002 | 7.5 | 21 | NO | NO |
CVE-2007-0884HIGH Buffer overflow in Roaring Penguin MIMEDefang 2.59 and 2.60 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via unspeci | Feb 12, 2007 | 7.5 | 20 | NO | NO |
Roaring Penguin pppoe (rp-ppoe), if installed or configured to run setuid root contrary to its design, allows local users to overwrite arbitrary files. NOTE: the developer has pub | Dec 23, 2004 | 2.1 | 11 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Roaring Penguin.
Media articles that mention a CVE ID that affects a product developed by Roaring Penguin — matched by CVE ID, not by vendor name.