Mail Security

Vendor:

First CVE: Feb 8, 2005 · Active for 21 years

19
Total CVEs
More Total CVEs than 93% of tracked products
2.1
Avg CVEs / Year
Higher CVE frequency than 73% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 75% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Mail Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 8, 2005
21 years ago
Most Recent CVE
Feb 21, 2020
2,346 days ago

CVE Severity & Scoring

Mail Security19 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local2 (10.5%)
Network0 (0.0%)
Unknown17 (89.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (10.5%)
High0 (0.0%)
Unknown17 (89.5%)
User Interaction
None1 (5.3%)
Unknown17 (89.5%)
Required1 (5.3%)
Privileges Required
Low1 (5.3%)
High0 (0.0%)
None1 (5.3%)
Unknown17 (89.5%)

Top CVEs

Signals from CVEs in this product scope (19 CVEs).

19 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, IBM Lotus Notes befor
Nov 10, 20079.335NONO
Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino
Feb 21, 20207.829NONO
Buffer overflow in the Lotus Freelance Graphics PRZ file viewer in Autonomy KeyView, as used in Symantec Mail Security (SMS) 6.x through 8.x, Symantec Brightmail and Messaging Gate
Jul 18, 20119.329NONO
Stack-based buffer overflow in Autonomy (formerly Verity) KeyView Viewer, Filter, and Export SDK before 9.2.0.12, as used by ActivePDF DocConverter, wp6sr.dll in IBM Lotus Notes 8.
Nov 10, 20079.328NONO
Heap-based buffer overflow in the DEC2EXE module for Symantec AntiVirus Library allows remote attackers to execute arbitrary code via a UPX compressed file containing a negative vi
Feb 8, 20057.527NONO
Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 th
Mar 5, 201010.026NONO
Buffer overflow in xlssr.dll in the Autonomy KeyView XLS viewer (aka File Viewer for Excel), as used in IBM Lotus Notes 5.x through 8.5.x, Symantec Mail Security, Symantec BrightMa
Sep 1, 20099.326NONO
The Decomposer component in multiple Symantec products allows remote attackers to cause a denial of service (infinite loop) via a certain value in the PACK_SIZE field of a RAR arch
Oct 5, 20079.326NONO
Symantec Endpoint Protection Manager (SEPM) and Symantec Mail Security for MS Exchange (SMSMSE), prior to versions 14.2 RU2 and 7.5.x respectively, may be susceptible to a privileg
Nov 15, 20197.825NONO
Stack-based buffer overflow in wp6sr.dll in the Autonomy KeyView SDK 10.4 and earlier, as used in IBM Lotus Notes, Symantec Mail Security (SMS) products, Symantec BrightMail Applia
Mar 18, 20099.325NONO

Exploit Exposure

Signals from CVEs in this product scope (19 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (19 CVEs).

Media Mentions

Signals from CVEs in this product scope (19 CVEs).

Top CNAs Publishing CVEs For Mail Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
8.0.2110.03.7%00
8.0.1110.03.7%00
8.039.54.9%00
7.5.8110.03.7%00
7.5.7110.03.7%00
7.5.629.74.7%00
7.5.5.3239.55.4%00
7.5.4.2929.74.7%00
7.5..4.2919.36.8%00
7.5.3.2539.55.4%00
7.559.38.8%00
6.5.717.88.1%00
6.0.829.74.7%00
6.0.739.55.4%00
6.0.639.55.4%00
6.0.039.35.0%00
5.1.037.94.0%00
5.0.13110.03.7%00
5.0.1.20029.36.2%00
5.0.1229.74.7%00