Vulnerabilities > Mailenable > Mailenable Professional > 1.17

DATE CVE VULNERABILITY TITLE RISK
2007-02-15 CVE-2007-0652 HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client
Cross-site request forgery (CSRF) vulnerability in MailEnable Professional before 2.37 allows remote attackers to modify arbitrary configurations and perform unauthorized actions as arbitrary users via a link or IMG tag.
network
high complexity
mailenable
5.1
2007-02-15 CVE-2007-0651 HTML Injection and Cross-Site Scripting vulnerability in MailEnable Web Mail Client
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Professional before 2.37 allow remote attackers to inject arbitrary Javascript script via (1) e-mail messages and (2) the ID parameter to (a) right.asp, (b) Forms/MAI/list.asp, and (c) Forms/VCF/list.asp in mewebmail/base/default/lang/EN/.
network
mailenable
4.3
2006-06-28 CVE-2006-3277 Resource Management Errors vulnerability in Mailenable Enterprise and Mailenable Professional
The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.
network
low complexity
mailenable CWE-399
5.0
2006-04-15 CVE-2006-1792 Remote Security vulnerability in Mailenable products
Unspecified vulnerability in the POP service in MailEnable Standard Edition before 1.94, Professional Edition before 1.74, and Enterprise Edition before 1.22 has unknown attack vectors and impact related to "authentication exploits".
network
low complexity
mailenable
critical
10.0
2006-03-21 CVE-2006-1338 Resource Management Errors vulnerability in Mailenable Enterprise and Mailenable Professional
Webmail in MailEnable Professional Edition before 1.73 and Enterprise Edition before 1.21 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors involving "incorrectly encoded quoted-printable emails".
network
low complexity
mailenable CWE-399
5.0
2006-02-01 CVE-2006-0503 Remote Denial of Service vulnerability in MailEnable Professional EXAMINE Command
IMAP service in MailEnable Professional Edition before 1.72 allows remote attackers to cause a denial of service (service crash) via unspecified vectors involving the EXAMINE command.
network
low complexity
mailenable
5.0
2005-07-12 CVE-2005-2223 Denial-Of-Service vulnerability in Mailenable Professional and Mailenable Standard
Unknown vulnerability in the SMTP service in MailEnable Standard before 1.9 and Professional before 1.6 allows remote attackers to cause a denial of service (crash) during authentication.
network
low complexity
mailenable
5.0
2005-07-12 CVE-2005-2222 Remote Security vulnerability in MailEnable Professional
Unknown vulnerability in the HTTPMail service in MailEnable Professional before 1.6 has unknown impact and attack vectors.
network
low complexity
mailenable
critical
10.0
2004-12-31 CVE-2004-2194 Remote Denial Of Service vulnerability in MailEnable
MailEnable Professional Edition before 1.53 and Enterprise Edition before 1.02 allows remote attackers to cause a denial of service (crash) via malformed (1) SMTP or (2) IMAP commands.
network
low complexity
mailenable
5.0