Search Results (22 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2002-1434 1 Kerio 1 Kerio Mailserver 2025-04-03 N/A
Multiple cross-site scripting (XSS) vulnerabilities in the Web mail module of Kerio MailServer 5.0 allow remote attackers to execute HTML script as other users via certain URLs.
CVE-2004-1022 1 Kerio 3 Kerio Mailserver, Serverfirewall, Winroute Firewall 2025-04-03 N/A
Kerio Winroute Firewall before 6.0.7, ServerFirewall before 1.0.1, and MailServer before 6.0.5 use symmetric encryption for user passwords, which allows attackers to decrypt the user database and obtain the passwords by extracting the secret key from within the software.