Vulnerabilities > Mailenable > Mailenable > High

DATE CVE VULNERABILITY TITLE RISK
2023-01-13 CVE-2022-42136 Path Traversal vulnerability in Mailenable
Authenticated mail users, under specific circumstances, could add files with unsanitized content in public folders where the IIS user had permission to access.
network
low complexity
mailenable CWE-22
8.8
2019-01-16 CVE-2015-9277 Path Traversal vulnerability in Mailenable
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/..
network
low complexity
mailenable CWE-22
7.5
2007-02-15 CVE-2007-0955 Denial-Of-Service vulnerability in MailEnable Professional
The NTLM_UnPack_Type3 function in MENTLM.dll in MailEnable Professional 2.35 and earlier allows remote attackers to cause a denial of service (application crash) via certain base64-encoded data following an AUTHENTICATE NTLM command to the imap port (143/tcp), which results in an out-of-bounds read.
network
low complexity
mailenable
7.8
2006-03-21 CVE-2006-1337 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Mailenable
Buffer overflow in the POP 3 (POP3) service in MailEnable Standard Edition before 1.93, Professional Edition before 1.73, and Enterprise Edition before 1.21 allows remote attackers to execute arbitrary code via unknown vectors before authentication.
network
low complexity
mailenable CWE-119
7.5