📦

mailenable_professional

Vendor: mailenable

Actively Exploited 0 CISA KEV List
PoC / Exploits 15 Code Available
Total RCEs 7 Remote Access
Total CVEs 40 Total Indexed
Avg. EPSS 18.05% Exploit Prob.
Latest CVE CVE-2008-1275 Mar 10

Security Vulnerability Index

Page 3 / 4
7.8 CVSS

Multiple unspecified vulnerabilities in MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allow attackers to cause a denial of service (crash) via invalid IMAP commands.

EPSS: 0.49%
4.0 CVSS
CVE-2005-3813
Exploit Found

IMAP service (meimaps.exe) of MailEnable Professional 1.7 and Enterprise 1.1 allows remote authenticated attackers to cause a denial of service (application crash) by using RENAME with a non-existent mailbox, a different vulnerability than CVE-2005-3690.

EPSS: 6.22%
7.5 CVSS

Stack-based buffer overflow in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to execute arbitrary code via a long mailbox name in the (1) select, (2) create, (3) delete, (4) rename, (5) subscribe, or (6) unsubscribe commands.

EPSS: 11.91%
5.0 CVSS

Directory traversal vulnerability in the IMAP service (meimaps.exe) of MailEnable Professional 1.6 and earlier and Enterprise 1.1 and earlier allows remote attackers to create or rename arbitrary mail directories via the mailbox name argument of the (1) create or (2) rename commands.

EPSS: 4.06%
7.5 CVSS
CVE-2005-3155
RCE Exploit Found

Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.

EPSS: 86.48%
7.2 CVSS
CVE-2005-2278
RCE Exploit Found

Stack-based buffer overflow in the IMAP daemon (imapd) in MailEnable Professional 1.54 allows remote authenticated users to execute arbitrary code via the status command with a long mailbox name.

EPSS: 71.50%
10.0 CVSS

Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.

EPSS: 0.26%
5.0 CVSS

Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.

EPSS: 2.97%
5.0 CVSS

Unknown vulnerability in SMTP authentication for MailEnable allows remote attackers to cause a denial of service (crash).

EPSS: 2.43%
7.5 CVSS

Buffer overflow in the IMAP service for MailEnable Enterprise 1.04 and earlier and Professional 1.54 allows remote attackers to execute arbitrary code via a long AUTHENTICATE command.

EPSS: 17.20%