Alt-N / Mdaemon
39 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-29976 | An Authenticated Reflected Cross-site scripting at BCC Parameter was discovered in MDaemon before 22.0.0 . | MEDIUM | 5.4 | May 11, 2022 |
| CVE-2022-29975 | An Authenticated Reflected Cross-site scripting at CC Parameter was discovered in MDaemon before 22.0.0 . | MEDIUM | 5.4 | May 11, 2022 |
| CVE-2021-27183 | An issue was discovered in MDaemon before 20.0.4. Administrators can use Remote Administration to exploit an Arbitrary File Write vulnerability. An attacker is… | HIGH | 7.2 | Apr 14, 2021 |
| CVE-2021-27182 | An issue was discovered in MDaemon before 20.0.4. There is an IFRAME injection vulnerability in Webmail (aka WorldClient). It can be exploited via an email mes… | HIGH | 8.8 | Apr 14, 2021 |
| CVE-2021-27181 | An issue was discovered in MDaemon before 20.0.4. Remote Administration allows an attacker to perform a fixation of the anti-CSRF token. In order to exploit th… | HIGH | 8.8 | Apr 14, 2021 |
| CVE-2021-27180 | An issue was discovered in MDaemon before 20.0.4. There is Reflected XSS in Webmail (aka WorldClient). It can be exploited via a GET request. It allows perform… | MEDIUM | 6.1 | Apr 14, 2021 |
| CVE-2019-8984 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2). | MEDIUM | 6.1 | Feb 21, 2019 |
| CVE-2019-8983 | MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2). | MEDIUM | 6.1 | Feb 21, 2019 |
| CVE-2012-2584 | Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail me… | MEDIUM | 4.3 | Aug 12, 2012 |
| CVE-2008-6967 | Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site script… | MEDIUM | 5.0 | Aug 13, 2009 |
| CVE-2008-2631 | The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application cra… | MEDIUM | 5.0 | Jun 10, 2008 |
| CVE-2008-1358 | Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH comm… | MEDIUM | 6.5 | Mar 17, 2008 |
| CVE-2003-1471 | MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number. | MEDIUM | 6.3 | Oct 24, 2007 |
| CVE-2003-1470 | Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code… | HIGH | 9.0 | Oct 24, 2007 |
| CVE-2007-3622 | Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed mes… | LOW | 2.6 | Jul 9, 2007 |
| CVE-2006-5968 | MDaemon 9.0.5, 9.0.6, 9.51, and 9.53, and possibly other versions, installs the MDaemon application folder with insecure permissions (Users create files/direct… | MEDIUM | 4.6 | Nov 17, 2006 |
| CVE-2006-5709 | Unspecified vulnerability in WorldClient in Alt-N Technologies MDaemon before 9.50 has unknown impact and attack vectors related to a "JavaScript exploit." | HIGH | 10.0 | Nov 4, 2006 |
| CVE-2006-5708 | Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory… | HIGH | 7.5 | Nov 4, 2006 |
| CVE-2006-4364 | Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon… | MEDIUM | 5.0 | Aug 25, 2006 |
| CVE-2006-2646 | Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"… | HIGH | 7.5 | May 30, 2006 |
| CVE-2006-0925 | Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consump… | MEDIUM | 5.0 | Feb 28, 2006 |
| CVE-2005-4266 | WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a usern… | HIGH | 7.5 | Dec 15, 2005 |
| CVE-2005-4209 | WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject heade… | MEDIUM | 4.3 | Dec 13, 2005 |
| CVE-2004-2504 | The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new… | HIGH | 7.2 | Oct 25, 2005 |
| CVE-2004-2292 | Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server. | MEDIUM | 5.0 | Aug 4, 2005 |
Showing 1 to 25 of 39 CVEs