Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2025-26558

Disclosure Date: February 13, 2025 (last updated February 14, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in mkkmail Aparat Responsive allows DOM-Based XSS. This issue affects Aparat Responsive: from n/a through 1.3.
0
Attacker Value
Unknown

CVE-2022-46821

Disclosure Date: November 07, 2023 (last updated November 17, 2023)
Improper Neutralization of Formula Elements in a CSV File vulnerability in Jackmail & Sarbacane Emails & Newsletters with Jackmail.This issue affects Emails & Newsletters with Jackmail: from n/a through 1.2.22.
Attacker Value
Unknown

CVE-2006-7062

Disclosure Date: February 24, 2007 (last updated October 04, 2023)
calendar.php in Kamgaing Email System (kmail) 2.3 and earlier allows remote attackers to obtain the full path of the server via an invalid d parameter, which leaks the path in an error message.
0
Attacker Value
Unknown

CVE-2006-2104

Disclosure Date: April 29, 2006 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Kamgaing Email System (kmail) 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) d parameter to main.php, ordner parameter to (2) main.php, or (3) webdisk.php, (4) draft parameter to compose.php, or (5) m, or (6) y parameter to calendar.php.
0
Attacker Value
Unknown

CVE-2005-0404

Disclosure Date: May 02, 2005 (last updated February 22, 2025)
KMail 1.7.1 in KDE 3.3.2 allows remote attackers to spoof email information, such as whether the email has been digitally signed or encrypted, via HTML formatted email.
0
Attacker Value
Unknown

CVE-2004-2677

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Format string vulnerability in qwik-smtpd.c in QwikMail SMTP (qwik-smtpd) 0.3 and earlier allows remote attackers to execute arbitrary code via format specifiers in the (1) clientRcptTo array, and the (2) Received and (3) messageID variables, possibly involving HELO and hostname arguments.
0
Attacker Value
Unknown

CVE-2002-1193

Disclosure Date: October 28, 2002 (last updated February 22, 2025)
tkmail before 4.0beta9-8.1 allows local users to create or overwrite files as users via a symlink attack on temporary files.
0