Tumbleweed develops email security and messaging management appliances, including gateway firewalls and secure transport servers, with a concentrated vulnerability history spanning input validation and cross-site scripting issues alongside memory-safety concerns. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Tumbleweed over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-1724HIGH Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Ser | Apr 11, 2008 | 9.3 | 61 | NO | YES |
CVE-2006-3901HIGH Multiple stack-based buffer overflows in Tumbleweed Email Firewall (EMF) allow remote attackers to execute arbitrary code via an email attachment with an LHA archive that contains | Jul 27, 2006 | 7.5 | 20 | NO | NO |
CVE-2000-0772HIGH The installation of Tumbleweed Messaging Management System (MMS) 4.6 and earlier (formerly Worldtalk Worldsecure) creates a default account "sa" with no password. | Oct 20, 2000 | 7.5 | 19 | NO | NO |
CVE-2006-0487MEDIUM Multiple unspecified vulnerabilities in Tumbleweed MailGate Email Firewall (EMF) 6.x allow remote attackers to (1) trigger temporarily incorrect processing of an e-mail message und | Feb 1, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-4727MEDIUM Cross-site scripting (XSS) vulnerability in emfadmin/statusView.do in Tumbleweed EMF Administration Module 6.2.2 Build 4123, and possibly other versions before 6.3.2, allows remote | Dec 31, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Tumbleweed.
Media articles that mention a CVE ID that affects a product developed by Tumbleweed — matched by CVE ID, not by vendor name.