Ipswitch / Imail
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2011-1430 | The STARTTLS implementation in the server in Ipswitch IMail 11.03 and earlier does not properly restrict I/O buffering, which allows man-in-the-middle attacker… | MEDIUM | 6.8 | Mar 16, 2011 |
| CVE-2007-2795 | Multiple buffer overflows in Ipswitch IMail before 2006.21 allow remote attackers or authenticated users to execute arbitrary code via (1) the authentication f… | HIGH | 9.0 | Jan 27, 2009 |
| CVE-2007-5094 | Heap-based buffer overflow in iaspam.dll in the SMTP Server in Ipswitch IMail Server 8.01 through 8.11 allows remote attackers to execute arbitrary code via a… | HIGH | 7.5 | Sep 26, 2007 |
| CVE-2007-1637 | Multiple buffer overflows in the IMAILAPILib ActiveX control (IMailAPI.dll) in Ipswitch IMail Server before 2006.2 allow remote attackers to execute arbitrary… | HIGH | 9.3 | Mar 23, 2007 |
| CVE-2004-2423 | Unknown vulnerability in the Web calendaring component of Ipswitch IMail Server before 8.13 allows remote attackers to cause a denial of service (crash) via "s… | MEDIUM | 5.0 | Aug 18, 2005 |
| CVE-2004-2422 | Multiple features in Ipswitch IMail Server before 8.13 allow remote attackers to cause a denial of service (crash) via (1) a long sender field to the Queue Man… | MEDIUM | 5.0 | Aug 18, 2005 |
| CVE-2005-2160 | IMail stores usernames and passwords in cleartext in a cookie, which allows remote attackers to obtain sensitive information. | HIGH | 7.5 | Jul 6, 2005 |
| CVE-2005-1256 | Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Ho… | HIGH | 10.0 | May 25, 2005 |
| CVE-2005-1255 | Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8… | HIGH | 10.0 | May 25, 2005 |
| CVE-2005-1254 | Stack-based buffer overflow in the IMAP server for Ipswitch IMail 8.12 and 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticat… | MEDIUM | 5.0 | May 25, 2005 |
| CVE-2005-1252 | Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote atta… | MEDIUM | 5.0 | May 25, 2005 |
| CVE-2004-1520 | Stack-based buffer overflow in IPSwitch IMail 8.13 allows remote authenticated users to execute arbitrary code via a long IMAP DELETE command. | MEDIUM | 4.6 | Feb 19, 2005 |
| CVE-2004-0297 | Buffer overflow in the Lightweight Directory Access Protocol (LDAP) daemon (iLDAP.exe 3.9.15.10) in Ipswitch IMail Server 8.03 allows remote attackers to cause… | HIGH | 10.0 | Sep 1, 2004 |
| CVE-2002-1076 | Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HT… | HIGH | 7.5 | Apr 2, 2003 |
| CVE-2002-0777 | Buffer overflow in the LDAP component of Ipswitch IMail 7.1 and earlier allows remote attackers to execute arbitrary code via a long "bind DN" parameter. | HIGH | 10.0 | Apr 2, 2003 |
| CVE-2002-1077 | IPSwitch IMail Web Calendaring service (iwebcal) allows remote attackers to cause a denial of service (crash) via an HTTP POST request without a Content-Length… | MEDIUM | 5.0 | Aug 31, 2002 |
| CVE-2001-1287 | Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | HIGH | 7.5 | May 3, 2002 |
| CVE-2001-1286 | Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. via an HT… | HIGH | 7.5 | May 3, 2002 |
| CVE-2001-1285 | Directory traversal vulnerability in readmail.cgi for Ipswitch IMail 7.04 and earlier allows remote attackers to access the mailboxes of other users via a .. (… | MEDIUM | 5.0 | May 3, 2002 |
| CVE-2001-1284 | Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users. | HIGH | 7.5 | May 3, 2002 |
| CVE-2001-1283 | The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contai… | HIGH | 7.5 | May 3, 2002 |
| CVE-2001-1282 | Ipswitch IMail 7.04 and earlier records the physical path of attachments in an e-mail message header, which could allow remote attackers to obtain potentially… | MEDIUM | 5.0 | May 3, 2002 |
| CVE-2001-1281 | Web Messaging Server for Ipswitch IMail 7.04 and earlier allows remote authenticated users to change information for other users by modifying the olduser param… | MEDIUM | 5.0 | May 3, 2002 |
| CVE-2001-1280 | POP3 Server for Ipswitch IMail 7.04 and earlier generates different responses to valid and invalid user names, which allows remote attackers to determine users… | MEDIUM | 5.0 | May 3, 2002 |
| CVE-2001-1211 | Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains ho… | HIGH | 7.5 | Mar 15, 2002 |
Showing 1 to 25 of 38 CVEs