📦

imail

Vendor: ipswitch

Actively Exploited 0 CISA KEV List
PoC / Exploits 16 Code Available
Total RCEs 8 Remote Access
Total CVEs 47 Total Indexed
Avg. EPSS 11.77% Exploit Prob.
Latest CVE CVE-2011-1430 Mar 16

Security Vulnerability Index

Page 4 / 5
5.0 CVSS

Ipswitch IMAIL server 6.02 and earlier allows remote attackers to cause a denial of service via the AUTH CRAM-MD5 command.

EPSS: 1.55%
5.0 CVSS
CVE-2000-0056
Exploit Found

IMail IMONITOR status.cgi CGI script allows remote attackers to cause a denial of service with many calls to status.cgi.

EPSS: 1.13%
7.2 CVSS
CVE-1999-1497
Exploit Found

Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts.

EPSS: 0.54%
2.1 CVSS

IMail POP3 daemon uses weak encryption, which allows local users to read files.

EPSS: 0.02%
5.0 CVSS
CVE-1999-1551
Exploit Found

Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execute arbitrary commands via a long URL.

EPSS: 44.69%
10.0 CVSS
CVE-1999-1046
Exploit Found

Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long string to port 8181.

EPSS: 4.56%
4.6 CVSS
CVE-1999-1171
Exploit Found

IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

EPSS: 0.01%
4.6 CVSS
CVE-1999-1170
Exploit Found

IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" registry key to 1920.

EPSS: 0.01%