Alt-n
Alt-n Mdaemon: vulnerabilidades y CVE
Alt-n Mdaemon tiene 28 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE28
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2008-6967 | Media (5) | 1.2% | — | 13 ago 2009 | Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a different… |
| CVE-2007-3622 | Baja (2.6) | 1.4% | — | 9 jul 2007 | Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages. |
| CVE-2006-5968 | Media (4.6) | 0.40% | — | 17 nov 2006 | MDaemon 9.0.5, 9.0.6, 9.51, and 9.53, and possibly other versions, installs the MDaemon application folder with insecure permissions (Users create files/directories), which allows local users to execute arbitrary code… |
| CVE-2006-5708 | Alta (7.5) | 1.0% | — | 4 nov 2006 | Multiple unspecified vulnerabilities in MDaemon and WorldClient in Alt-N Technologies MDaemon before 9.50 allow attackers to cause a denial of service (memory consumption) via unspecified vectors resulting in memory… |
| CVE-2006-5709 | Alta (10) | 1.6% | — | 4 nov 2006 | Unspecified vulnerability in WorldClient in Alt-N Technologies MDaemon before 9.50 has unknown impact and attack vectors related to a "JavaScript exploit." |
| CVE-2006-4364 | Media (5) | 57% | — | 27 ago 2006 | Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via long strings… |
| CVE-2006-2646 | Alta (7.5) | 4.5% | — | 30 may 2006 | Buffer overflow in Alt-N MDaemon, possibly 9.0.1 and earlier, allows remote attackers to execute arbitrary code via a long A0001 argument that begins with a '"' (double quote). |
| CVE-2006-0925 | Media (5) | 3.1% | — | 28 feb 2006 | Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names… |
| CVE-2005-4266 | Alta (7.5) | 1.3% | — | 15 dic 2005 | WorldClient.dll in Alt-N MDaemon and WorldClient 8.1.3 trusts a Session parameter that contains a randomly generated session ID that is associated with a username, which allows remote attackers to perform actions as… |
| CVE-2005-4209 | Media (4.3) | 2.1% | — | 13 dic 2005 | WorldClient webmail in Alt-N MDaemon 8.1.3 allows remote attackers to prevent arbitrary users from accessing their inboxes via script tags in the Subject header of an e-mail message, which prevents the user from being… |
| CVE-2004-1546 | Media (5) | 31% | — | 31 dic 2004 | Multiple buffer overflows in MDaemon 6.5.1 allow remote attackers to cause a denial of service (application crash) via a long (1) SAML, SOML, SEND, or MAIL command to the SMTP server or (2) LIST command to the IMAP… |
| CVE-2004-2504 | Alta (7.2) | 0.48% | — | 31 dic 2004 | The GUI in Alt-N Technologies MDaemon 7.2 and earlier, including 6.8, executes child processes such as NOTEPAD.EXE with SYSTEM privileges when users create new files, which allows local users with physical access to… |
| CVE-2004-2292 | Media (5) | 12% | — | 31 dic 2004 | Buffer overflow in Alt-N MDaemon 7.0.1 allows remote attackers to cause a denial of service (application crash) via a long STATUS command to the IMAP server. |
| CVE-2003-1471 | Media (6.3) | 1.1% | — | 31 dic 2003 | MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service (crash) via a (1) DELE or (2) UIDL with a negative number. |
| CVE-2003-1470 | Alta (9) | 5.0% | — | 31 dic 2003 | Buffer overflow in IMAP service in MDaemon 6.7.5 and earlier allows remote authenticated users to cause a denial of service (crash) and execute arbitrary code via a CREATE command with a long mailbox name. |
| CVE-2003-1200 | Alta (7.5) | 65% | — | 29 dic 2003 | Stack-based buffer overflow in FORM2RAW.exe in Alt-N MDaemon 6.5.2 through 6.8.5 allows remote attackers to execute arbitrary code via a long From parameter to Form2Raw.cgi. |
| CVE-2002-1539 | Media (5) | 3.2% | — | 31 mar 2003 | Buffer overflow in MDaemon POP server 6.0.7 and earlier allows remote authenticated users to cause a denial of service via long (1) DELE or (2) UIDL arguments. |
| CVE-2002-1738 | Media (5) | 1.3% | — | 31 dic 2002 | Alt-N Technologies MDaemon 5.0.5.0 and earlier creates a default MDaemon mail account with a password of MServer, which could allow remote attackers to send anonymous email. |
| CVE-2002-1740 | Baja (2.1) | 1.1% | — | 31 dic 2002 | Buffer overflow in WorldClient.cgi in WorldClient in Alt-N Technologies MDaemon 5.0.5.0 and earlier allows local users to execute arbitrary code via a long folder name (NewFolder parameter). |
| CVE-2001-0584 | Baja (2.1) | 0.93% | — | 22 ago 2001 | IMAP server in Alt-N Technologies MDaemon 3.5.6 allows a local user to cause a denial of service (hang) via long (1) SELECT or (2) EXAMINE commands. |
| CVE-2001-0583 | Media (5) | 1.6% | — | 22 ago 2001 | Alt-N Technologies MDaemon 3.5.4 allows a remote attacker to create a denial of service via the URL request of a MS-DOS device (such as GET /aux) to (1) the Worldclient service at port 3000, or (2) the Webconfig service… |
| CVE-2001-0104 | Alta (7.2) | 0.40% | — | 12 feb 2001 | MDaemon Pro 3.5.1 and earlier allows local users to bypass the "lock server" security setting by pressing the Cancel button at the password prompt, then pressing the enter key. |
| CVE-2001-0064 | Media (5) | 1.9% | — | 12 feb 2001 | Webconfig, IMAP, and other services in MDaemon 3.5.0 and earlier allows remote attackers to cause a denial of service via a long URL terminated by a "\r\n" string. |
| CVE-2000-1021 | Alta (7.5) | 3.8% | — | 11 dic 2000 | Heap overflow in WebConfig in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. |
| CVE-2000-1020 | Alta (7.5) | 2.3% | — | 11 dic 2000 | Heap overflow in Worldclient in Mdaemon 3.1.1 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary commands via a long URL. |
| CVE-2000-0716 | Baja (2.6) | 1.1% | — | 20 oct 2000 | WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user's email. |
| CVE-2000-0501 | Baja (2.6) | 4.1% | — | 16 jun 2000 | Race condition in MDaemon 2.8.5.0 POP server allows local users to cause a denial of service by entering a UIDL command and quickly exiting the server. |
| CVE-2000-0399 | Media (5) | 1.3% | — | 24 may 2000 | Buffer overflow in MDaemon POP server allows remote attackers to cause a denial of service via a long user name. |