Show filters
37 Total Results
Displaying 21-30 of 37
Sort by:
Attacker Value
Unknown

CVE-2017-9046

Disclosure Date: May 21, 2017 (last updated November 26, 2024)
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a mailto: link on a remote web page triggers the attack.
0
Attacker Value
Unknown

CVE-2017-5223

Disclosure Date: January 16, 2017 (last updated November 25, 2024)
An issue was discovered in PHPMailer before 5.2.22. PHPMailer's msgHTML method applies transformations to an HTML document to make it usable as an email message body. One of the transformations is to convert relative image URLs into attachments using a script-provided base directory. If no base directory is provided, it resolves to /, meaning that relative image URLs get treated as absolute local file paths and added as attachments. To form a remote vulnerability, the msgHTML method must be called, passed an unfiltered, user-supplied HTML document, and must not set a base directory.
0
Attacker Value
Unknown

CVE-2016-10033

Disclosure Date: December 30, 2016 (last updated February 15, 2024)
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a \" (backslash double quote) in a crafted Sender property.
Attacker Value
Unknown

CVE-2016-10045

Disclosure Date: December 30, 2016 (last updated November 25, 2024)
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code by leveraging improper interaction between the escapeshellarg function and internal escaping performed in the mail function in PHP. NOTE: this vulnerability exists because of an incorrect fix for CVE-2016-10033.
Attacker Value
Unknown

CVE-2015-8476

Disclosure Date: December 16, 2015 (last updated October 05, 2023)
Multiple CRLF injection vulnerabilities in PHPMailer before 5.2.14 allow attackers to inject arbitrary SMTP commands via CRLF sequences in an (1) email address to the validateAddress function in class.phpmailer.php or (2) SMTP command to the sendCommand function in class.smtp.php, a different vulnerability than CVE-2012-0796.
0
Attacker Value
Unknown

CVE-2009-3838

Disclosure Date: November 02, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.
0
Attacker Value
Unknown

CVE-2007-4440

Disclosure Date: August 21, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, allows remote attackers to execute arbitrary code via a long AUTH CRAM-MD5 string. NOTE: this might overlap CVE-2006-5961.
0
Attacker Value
Unknown

CVE-2007-3215

Disclosure Date: June 14, 2007 (last updated October 04, 2023)
PHPMailer 1.7, when configured to use sendmail, allows remote attackers to execute arbitrary shell commands via shell metacharacters in the SendmailSend function in class.phpmailer.php.
0
Attacker Value
Unknown

CVE-2007-1373

Disclosure Date: March 10, 2007 (last updated October 04, 2023)
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers to execute arbitrary code via a long LOGIN command. NOTE: this might be the same issue as CVE-2006-5961.
0
Attacker Value
Unknown

CVE-2006-3483

Disclosure Date: July 10, 2006 (last updated October 04, 2023)
PHPMailList 1.8.0 stores sensitive information under the web document root iwth insufficient access control, which allows remote attackers to obtain email addresses of subscribers, configuration information, and the admin username and password via direct requests to (1) list.dat or (2) ml_config.dat.
0