VYPR

Vendor CVEs

Gfi

All CVEs

60 total · sorted by risk
  • CVE-2026-48536MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated attackers to inject arbitrary web script or HTML via the SMTP server address parameter to /Archiver/GeneralSettingsWizard.aspx. The…

  • CVE-2026-48535MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the proxy server address parameter to /Archiver/CallHomeSettingsWizard.aspx.…

  • CVE-2026-48534MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter to /Archiver/ImapServerWizard.aspx. The injected payload is…

  • CVE-2026-48532MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/FAARetentionPolicyWizard.aspx.…

  • CVE-2026-48531MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attackers to inject arbitrary web script or HTML via the policy name parameter to /Archiver/RetentionPolicyWizard.aspx. The injected…

  • CVE-2026-48530MedJul 23, 2026
    risk 0.00cvss 5.4epss 0.00

    GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated attackers to inject arbitrary web script or HTML via the rule name and email criteria parameters to…

  • CVE-2010-5254Sep 7, 2012
    risk 0.00cvss epss 0.00

    Untrusted search path vulnerability in GFI Backup 3.1 Build 20100730 2009 Home Edition allows local users to gain privileges via a Trojan horse ArmAccess.dll file in the current working directory, as demonstrated by a directory that contains a .gbc or .gbt file. NOTE: some of…

  • CVE-2005-3182Oct 20, 2005
    risk 0.00cvss epss 0.04

    Buffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers such as (1) Host and (2) Accept in HTTP requests. NOTE: the vendor suggests that this issues is "in an underlying Microsoft technology"…

  • CVE-2005-0604May 2, 2005
    risk 0.00cvss epss 0.00

    lnss.exe in GFI Languard Network Security Scanner 5.0 stores the username and password in memory in plaintext, which could allow local administrators to obtain domain administrator credentials.

  • CVE-2004-1312Jan 3, 2005
    risk 0.00cvss epss 0.02

    A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which…

Page 2 of 2