Filtered by vendor Icewarp Subscriptions
Total 65 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2015-1503 1 Icewarp 1 Mail Server 2024-08-06 N/A
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the file parameter to a webmail/client/skins/default/css/css.php page or .../. (dot dot dot slash dot) in the (2) script or (3) style parameter to webmail/old/calendar/minimizer/index.php.
CVE-2017-12844 1 Icewarp 1 Mail Server 2024-08-05 N/A
Cross-site scripting (XSS) vulnerability in the admin panel in IceWarp Mail Server 10.4.4 allows remote authenticated domain administrators to inject arbitrary web script or HTML via a crafted user name.
CVE-2017-7855 1 Icewarp 1 Server 2024-08-05 N/A
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.
CVE-2018-16324 1 Icewarp 1 Mail Server 2024-08-05 N/A
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
CVE-2018-7475 1 Icewarp 1 Mail Server 2024-08-05 6.1 Medium
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
CVE-2019-19265 1 Icewarp 1 Mail Server 2024-08-05 6.1 Medium
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
CVE-2019-19266 1 Icewarp 1 Mail Server 2024-08-05 5.4 Medium
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
CVE-2019-12593 1 Icewarp 1 Mail Server 2024-08-04 N/A
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
CVE-2020-27982 1 Icewarp 1 Mail Server 2024-08-04 6.1 Medium
IceWarp 11.4.5.0 allows XSS via the language parameter.
CVE-2020-25925 1 Icewarp 1 Webclient 2024-08-04 6.1 Medium
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
CVE-2020-14064 1 Icewarp 1 Mail Server 2024-08-04 6.5 Medium
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
CVE-2020-14066 1 Icewarp 1 Mail Server 2024-08-04 8.8 High
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
CVE-2020-14065 1 Icewarp 1 Mail Server 2024-08-04 6.5 Medium
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
CVE-2020-8512 1 Icewarp 1 Icewarp Server 2024-08-04 6.1 Medium
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
CVE-2021-36580 1 Icewarp 2 Icewarp Server, Mail Server 2024-08-04 6.1 Medium
Open Redirect vulnerability exists in IceWarp MailServer IceWarp Server Deep Castle 2 Update 1 (13.0.1.2) via the referer parameter.
CVE-2022-35115 1 Icewarp 1 Webclient Dc2 2024-08-03 9.8 Critical
IceWarp WebClient DC2 - Update 2 Build 9 (13.0.2.9) was discovered to contain a SQL injection vulnerability via the search parameter at /webmail/server/webmail.php.
CVE-2023-43319 1 Icewarp 1 Webclient 2024-08-02 6.1 Medium
Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
CVE-2023-41013 1 Icewarp 1 Icewarp 2024-08-02 6.1 Medium
Cross Site Scripting (XSS) in Webmail Calendar in IceWarp 10.3.1 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
CVE-2023-40779 1 Icewarp 1 Deep Castle G2 2024-08-02 6.1 Medium
An issue in IceWarp Mail Server Deep Castle 2 v.13.0.1.2 allows a remote attacker to execute arbitrary code via a crafted request to the URL.
CVE-2023-39700 1 Icewarp 1 Mail Server 2024-08-02 6.1 Medium
IceWarp Mail Server v10.4.5 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the color parameter.