📦

imail_server

Vendor: ipswitch

Actively Exploited 0 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 4 Remote Access
Total CVEs 46 Total Indexed
Avg. EPSS 23.25% Exploit Prob.
Latest CVE CVE-2017-12639 Oct 03

Security Vulnerability Index

Page 2 / 5
10.0 CVSS

Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.

EPSS: 74.88%
5.0 CVSS

Directory traversal vulnerability in the Web Calendaring server in Ipswitch Imail 8.13, and other versions before IMail Server 8.2 Hotfix 2, allows remote attackers to read arbitrary files via "..\" (dot dot backslash) sequences in the query string argument in a GET request to a non-existent .jsp file.

EPSS: 0.82%