Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2007-6385

Disclosure Date: December 15, 2007 (last updated October 04, 2023)
The proxy server in Kerio WinRoute Firewall before 6.4.1 does not properly enforce authentication for HTTPS pages, which has unknown impact and attack vectors. NOTE: it is not clear whether this issue crosses privilege boundaries.
0
Attacker Value
Unknown

CVE-2006-5420

Disclosure Date: October 20, 2006 (last updated October 04, 2023)
Kerio WinRoute Firewall 6.2.2 and earlier allows remote attackers to cause a denial of service (crash) via malformed DNS responses.
0
Attacker Value
Unknown

CVE-2006-2267

Disclosure Date: May 09, 2006 (last updated October 04, 2023)
Kerio WinRoute Firewall before 6.2.1 allows remote attackers to cause a denial of service (application crash) via unknown vectors in the "email protocol inspectors," possibly (1) SMTP and (2) POP3.
0
Attacker Value
Unknown

CVE-2006-0335

Disclosure Date: January 21, 2006 (last updated February 22, 2025)
Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving (1) long strings received from Active Directory and (2) the filtering of HTML.
0
Attacker Value
Unknown

CVE-2006-0336

Disclosure Date: January 21, 2006 (last updated February 22, 2025)
Kerio WinRoute Firewall before 6.1.4 Patch 2 allows attackers to cause a denial of service (CPU consumption and hang) via unknown vectors involving "browsing the web".
0
Attacker Value
Unknown

CVE-2005-4425

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Unspecified vulnerability in Kerio WinRoute Firewall before 6.1.3 allows remote attackers to cause a denial of service (crash) via certain RTSP streams.
0
Attacker Value
Unknown

CVE-2005-1062

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to quickly obtain passwords that are 5 characters or less via brute force methods.
0
Attacker Value
Unknown

CVE-2005-1063

Disclosure Date: April 29, 2005 (last updated February 22, 2025)
The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and MailServer up to 6.0.8 allows remote attackers to cause a denial of service (CPU consumption) via certain attacks that force the product to "compute unexpected conditions" and "perform cryptographic operations."
0
Attacker Value
Unknown

CVE-2004-1023

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.9, ServerFirewall before 1.0.1, and MailServer before 6.0.5, when installed on Windows based systems, do not modify the ACLs for critical files, which allows local users with Power Users privileges to modify programs, install malicious DLLs in the plug-ins folder, and modify XML files related to configuration.
0
Attacker Value
Unknown

CVE-2004-1022

Disclosure Date: January 10, 2005 (last updated February 22, 2025)
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.
0