Vulnerabilities > Ipswitch > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2004-12-31 | CVE-2004-2401 | Buffer Overrun vulnerability in Ipswitch Imail Express 8.03 Stack-based buffer overflow in Ipswitch IMail Express Web Messaging before 8.05 might allow remote attackers to execute arbitrary code via an HTML message with long "tag text." | 7.5 |
2002-12-31 | CVE-2002-1851 | Buffer Overflow vulnerability in Ipswitch WS FTP PRO 7.5 Buffer overflow in WS_FTP Pro 7.5 allows remote attackers to execute code on a client system via unknown attack vectors. | 7.5 |
2002-10-04 | CVE-2002-1076 | Buffer Overflow vulnerability in IPSwitch IMail Web Messaging HTTP Get Buffer overflow in the Web Messaging daemon for Ipswitch IMail before 7.12 allows remote attackers to execute arbitrary code via a long HTTP GET request for HTTP/1.0. | 7.5 |
2001-12-31 | CVE-2001-1211 | Privilege Escalation vulnerability in Ipswitch IMail Domain Administration Ipswitch IMail 7.0.4 and earlier allows attackers with administrator privileges to read and modify user alias and mailing list information for other domains hosted by the same server via the (1) aliasadmin or (2) listadm1 CGI programs, which do not properly verify that an administrator is the administrator for the target domain. | 7.5 |
2001-10-12 | CVE-2001-1287 | Buffer Overflow vulnerability in Ipswitch Imail 6.0.2/6.0.6/7.0.4 Buffer overflow in Web Calendar in Ipswitch IMail 7.04 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | 7.5 |
2001-10-12 | CVE-2001-1286 | Unspecified vulnerability in Ipswitch Imail 6.0.2/6.0.6/7.0.4 Ipswitch IMail 7.04 and earlier stores a user's session ID in a URL, which could allow remote attackers to hijack sessions by obtaining the URL, e.g. | 7.5 |
2001-10-12 | CVE-2001-1284 | Unspecified vulnerability in Ipswitch Imail 6.0.2/6.0.6/7.0.4 Ipswitch IMail 7.04 and earlier uses predictable session IDs for authentication, which allows remote attackers to hijack sessions of other users. | 7.5 |
2001-10-12 | CVE-2001-1283 | Denial of Service vulnerability in Ipswitch Imail 6.0.2/6.0.6/7.0.4 The webmail interface for Ipswitch IMail 7.04 and earlier allows remote authenticated users to cause a denial of service (crash) via a mailbox name that contains a large number of . | 7.5 |
2001-06-27 | CVE-2001-0494 | Unspecified vulnerability in Ipswitch Imail Buffer overflow in IPSwitch IMail SMTP server 6.06 and possibly prior versions allows remote attackers to execute arbitrary code via a long From: header. | 7.5 |
1999-12-21 | CVE-1999-1497 | Weak Password Encryption vulnerability in IMail Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to read passwords for e-mail accounts. | 7.2 |