Rockliffe's vulnerability footprint centers on a focused line of email and messaging products, primarily MailSite and MailSite Express, that occupy a niche but visible position in on-premises collaboration infrastructure. The recurring exposure pattern reflects file-handling weaknesses, notably unrestricted file uploads with dangerous types, which are characteristic of email gateway and content-filtering architectures. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockliffe over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0128HIGH Buffer overflow in the IMAP service of Rockliffe MailSite before 6.1.22.1 allows remote attackers to have an unknown impact via unknown attack vectors. | Jan 9, 2006 | 10.0 | 25 | NO | NO |
CVE-2000-0398HIGH Buffer overflow in wconsole.dll in Rockliffe MailSite Management Agent allows remote attackers to execute arbitrary commands via a long query_string parameter in the HTTP GET reque | May 24, 2000 | 10.0 | 25 | NO | NO |
CVE-2006-0341MEDIUM Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the que | Jan 6, 2006 | 4.3 | 21 | NO | YES |
CVE-2006-0342HIGH RockLiffe MailSite HTTP Mail management agent (httpma) 7.0.3.1 allows remote attackers to cause a denial of service (CPU consumption and crash) via a malformed query string contain | Jan 21, 2006 | 7.8 | 20 | NO | NO |
CVE-2005-3430HIGH Incomplete blacklist vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to upload and execute arbitrary script files by giving the files specific ext | Nov 2, 2005 | 7.5 | 20 | NO | NO |
CVE-2006-0130HIGH Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of | Jan 9, 2006 | 7.5 | 19 | NO | NO |
CVE-2006-0790MEDIUM Rockliffe MailSite 7.0 and earlier allows remote attackers to cause a denial of service by sending crafted LDAP packets to port 389/TCP, as demonstrated by the ProtoVer LDAP testsu | Feb 19, 2006 | 5.0 | 16 | NO | NO |
CVE-2006-0129MEDIUM Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier generates different responses depending on whether or not a username is valid, | Jan 9, 2006 | 5.0 | 15 | NO | NO |
CVE-2005-3431MEDIUM Absolute path traversal vulnerability in Rockliffe MailSite Express before 6.1.22 allows remote attackers to read arbitrary files via a full pathname in the AttachPath field of a m | Nov 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-3287MEDIUM Incomplete blacklist vulnerability in Mailsite Express allows remote attackers to upload and possibly execute files via attachments with executable extensions such as ASPX, which a | Oct 23, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockliffe.
Media articles that mention a CVE ID that affects a product developed by Rockliffe — matched by CVE ID, not by vendor name.