VYPR

Mail Server

by Ability

CVEs (5)

  • CVE-2017-17752MedDec 20, 2017
    risk 0.43cvss 6.1epss 0.01

    Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.

  • CVE-2019-9557MedMar 12, 2019
    risk 0.40cvss 6.1epss 0.01

    Ability Mail Server 4.2.6 has Persistent Cross Site Scripting (XSS) via the body e-mail body. To exploit the vulnerability, the victim must open an email with malicious Javascript inserted into the body of the email as an iframe.

  • CVE-2004-2494Dec 31, 2004
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitrary web script or HTML via the erromsg parameter.

  • CVE-2007-6101Nov 23, 2007
    risk 0.00cvss epss 0.01

    Ability Mail Server before 2.61 allows remote authenticated users to cause a denial of service (daemon crash) via (1) malformed number list ranges in unspecified IMAP commands, and possibly (2) a blank string in unspecified messages.

  • CVE-2004-2495Dec 31, 2004
    risk 0.00cvss epss 0.02

    The (1) Webmail, (2) admin, and (3) SMTP services in Ability Mail Server 1.18 allow remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous connections to the service.