Merak / Mail Server
23 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2006-0817 | Absolute path directory traversal vulnerability in (a) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (b) VisNetic MailServer befo… | MEDIUM | 5.0 | Jul 18, 2006 |
| CVE-2006-0818 | Absolute path directory traversal vulnerability in (1) MERAK Mail Server for Windows 8.3.8r with before IceWarp Web Mail 5.6.1 and (2) VisNetic MailServer befo… | MEDIUM | 4.0 | Jul 18, 2006 |
| CVE-2005-4559 | mail/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly initialize t… | MEDIUM | 5.0 | Dec 28, 2005 |
| CVE-2005-4558 | IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, does not properly restrict acceptable values for th… | MEDIUM | 6.5 | Dec 28, 2005 |
| CVE-2005-4557 | dir/include.html in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, allows remote attackers to incl… | MEDIUM | 5.0 | Dec 28, 2005 |
| CVE-2005-4556 | PHP remote file include vulnerability in IceWarp Web Mail 5.5.1, as used by Merak Mail Server 8.3.0r and VisNetic Mail Server version 8.3.0 build 1, when regis… | HIGH | 7.5 | Dec 28, 2005 |
| CVE-2005-3133 | Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to… | MEDIUM | 5.0 | Oct 4, 2005 |
| CVE-2005-3132 | MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allows remote attackers to obtain sensitive information via a direct reque… | MEDIUM | 5.0 | Oct 4, 2005 |
| CVE-2005-3131 | Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earlier versions, allow remote attack… | MEDIUM | 4.3 | Oct 4, 2005 |
| CVE-2005-1491 | Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to (1) move their home directory via viewaction.html or (2) move arbitrar… | MEDIUM | 4.6 | May 11, 2005 |
| CVE-2005-1490 | Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2, when the mailbox.dat file does not exist, allows remote authenticated users to determine if a file exists… | LOW | 2.1 | May 11, 2005 |
| CVE-2005-1489 | Unknown vulnerability in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allows remote authenticated users to obtain the full path of the server via certai… | MEDIUM | 5.0 | May 11, 2005 |
| CVE-2005-1488 | Multiple cross-site scripting (XSS) vulnerabilities in Merak Mail Server 8.0.3 with Icewarp Web Mail 5.4.2 allow remote authenticated users to inject arbitrary… | LOW | 1.9 | May 11, 2005 |
| CVE-2004-1722 | SQL injection vulnerability in calendar.html in Merak Mail Server 5.2.7 allows remote attackers to execute arbitrary SQL statements via the schedule parameter. | HIGH | 7.5 | Feb 26, 2005 |
| CVE-2004-1721 | The (1) function.php or (2) function.view.php scripts in Merak Mail Server 5.2.7 allow remote attackers to read arbitrary PHP files via a direct HTTP request t… | MEDIUM | 5.0 | Feb 26, 2005 |
| CVE-2004-1720 | The (1) address.html and possibly (2) calendar.html pages in Merak Mail Server 5.2.7 allow remote attackers to gain sensitive information via an invalid HTTP r… | MEDIUM | 5.0 | Feb 26, 2005 |
| CVE-2004-1719 | Multiple cross-site scripting (XSS) vulnerabilities in Merak Webmail Server 5.2.7 allow remote attackers to inject arbitrary web script or HTML via the (1) cat… | MEDIUM | 4.3 | Feb 26, 2005 |
| CVE-2004-1674 | viewaction.html in Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to (1) delete arbitrary files via th… | HIGH | 7.5 | Feb 20, 2005 |
| CVE-2004-1670 | Multiple directory traversal vulnerabilities Merak Mail Server 7.4.5 with Icewarp Web Mail 5.2.7, and possibly other versions, allow remote attackers to (1) cr… | HIGH | 7.5 | Feb 20, 2005 |
| CVE-2004-1669 | Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute… | MEDIUM | 4.3 | Feb 20, 2005 |
| CVE-2005-0322 | MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 and Mail Server 7.6.4r with Icewarp Mail Server 5.3.2 uses weak encryption in the (1) users.cfg, (2) settin… | HIGH | 7.2 | Feb 10, 2005 |
| CVE-2005-0321 | MERAK Mail Server 7.6.0 with Icewarp Web Mail 5.3.0 allows remote authenticated users to gain sensitive information via an HTTP request to (1) calendar_d.html,… | LOW | 2.1 | Feb 10, 2005 |
| CVE-2002-0258 | Merak Mail IceWarp Web Mail uses a static identifier as a user session ID that does not change across sessions, which could allow remote attackers with access… | HIGH | 7.5 | May 3, 2002 |
Showing 1 to 23 of 23 CVEs