Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown

CVE-2018-17792

Disclosure Date: July 19, 2019 (last updated November 27, 2024)
MDaemon Webmail (formerly WorldClient) has CSRF.
0
Attacker Value
Unknown

CVE-2019-13612

Disclosure Date: July 16, 2019 (last updated November 27, 2024)
MDaemon Email Server 19 through 20.0.1 skips SpamAssassin checks by default for e-mail messages larger than 2 MB (and limits checks to 10 MB even with special configuration), which is arguably inconsistent with currently popular message sizes. This might interfere with risk management for malicious e-mail, if a customer deploys a server with sufficient resources to scan large messages.
0
Attacker Value
Unknown

CVE-2019-8983

Disclosure Date: February 21, 2019 (last updated November 27, 2024)
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 1 of 2).
0
Attacker Value
Unknown

CVE-2019-8984

Disclosure Date: February 21, 2019 (last updated November 27, 2024)
MDaemon Webmail 14.x through 18.x before 18.5.2 has XSS (issue 2 of 2).
0
Attacker Value
Unknown

CVE-2012-2584

Disclosure Date: August 12, 2012 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Alt-N MDaemon Free 12.5.4 allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) the Cascading Style Sheets (CSS) expression property in conjunction with a CSS comment within the STYLE attribute of an IMG element, (2) the CSS expression property in conjunction with multiple CSS comments within the STYLE attribute of an arbitrary element, or (3) an innerHTML attribute within an XML document.
0
Attacker Value
Unknown

CVE-2008-6967

Disclosure Date: August 13, 2009 (last updated October 04, 2023)
Multiple unspecified vulnerabilities in WorldClient in Alt-N MDaemon before 10.02 have unknown impact and attack vectors, probably related to cross-site scripting (XSS) and WorldClient DLL 10.0.1, a different vulnerability than CVE-2008-6893.
0
Attacker Value
Unknown

CVE-2008-2631

Disclosure Date: June 10, 2008 (last updated October 04, 2023)
The WordClient interface in Alt-N Technologies MDaemon 9.6.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted HTTP POST request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown

CVE-2008-1358

Disclosure Date: March 17, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to execute arbitrary code via a FETCH command with a long BODY.
0
Attacker Value
Unknown

CVE-2007-3622

Disclosure Date: July 09, 2007 (last updated October 04, 2023)
Unspecified vulnerability in DomainPOP in Alt-N Technologies MDaemon before 9.61 allows remote attackers to cause a denial of service (crash) via malformed messages.
0
Attacker Value
Unknown

CVE-2006-5968

Disclosure Date: November 17, 2006 (last updated October 04, 2023)
MDaemon 9.0.5, 9.0.6, 9.51, and 9.53, and possibly other versions, installs the MDaemon application folder with insecure permissions (Users create files/directories), which allows local users to execute arbitrary code by creating malicious RASAPI32.DLL or MPRAPI.DLL libraries in the MDaemon\APP folder, which is an untrusted search path element due to insecure permissions.
0