CVE-2010-3095
- EPSS 0.07%
- Veröffentlicht 12.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:01
mailscanner before 4.79.11-2.1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files. NOTE: this issue exists because of an incomplete fix for CVE-2008-5313.
CVE-2010-3292
- EPSS 0.03%
- Veröffentlicht 12.11.2019 21:15:10
- Zuletzt bearbeitet 21.11.2024 01:18:27
The update{_bad,}_phishing_sites scripts in mailscanner 4.79.11-2 downloads files and trusts them without using encryption (e.g., https) or digital signature checking which could allow an attacker to replace certain configuration files (e.g., phishin...
CVE-2010-3293
- EPSS 0.06%
- Veröffentlicht 28.10.2019 15:15:12
- Zuletzt bearbeitet 21.11.2024 01:18:27
mailscanner can allow local users to prevent virus signatures from being updated
CVE-2008-5312
- EPSS 0.02%
- Veröffentlicht 03.12.2008 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
mailscanner 4.55.10 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) panda-autoupdate.new, (4) trend...
CVE-2008-5313
- EPSS 0.02%
- Veröffentlicht 03.12.2008 17:30:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
mailscanner 4.68.8 and other versions before 4.74.16-1 might allow local users to overwrite arbitrary files via a symlink attack on certain temporary files used by the (1) f-prot-autoupdate, (2) clamav-autoupdate, (3) avast-autoupdate, and (4) f-prot...
CVE-2005-3470
- EPSS 0.82%
- Veröffentlicht 02.11.2005 23:02:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
SQL injection vulnerability in in the authenticate function in MailWatch for MailScanner 1.0.2 allows remote attackers to execute arbitrary SQL commands.
CVE-2005-1706
- EPSS 0.31%
- Veröffentlicht 24.05.2005 04:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
Unknown vulnerability in MailScanner 4.41.3 and earlier, related to "incomplete reporting of viruses in zip files," allows remote attackers to bypass virus detection.
CVE-2002-2228
- EPSS 0.2%
- Veröffentlicht 31.12.2002 05:00:00
- Zuletzt bearbeitet 03.04.2025 01:03:51
MailScanner before 4.0 5-1 and before 3.2 6-1 allows remote attackers to bypass protection via attachments with a filename with (1) extra leading spaces, (2) extra trailing spaces, or (3) alternate character encodings that cannot be processed by Mail...