emumail CVE Vulnerabilities & CVE List (6)

Products (CPE): — CVEs: 6

emumail vulnerability overview

This page aggregates publicly disclosed CVE and security risk information related to emumail, with CVSS, EPSS, publication dates, and vulnerability intelligence data to help assess potential risk and remediation priority.

Vulnerability distribution trend (last 24 months)

Showing 16 of 6 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2004-2385 EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for init.emu. [email protected] 5.0 4.82% 2004-12-31 2026-04-16
CVE-2004-2334 Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web script or HTML via (1) a hex-encoded value to the variable parameter in emumail.fcgi, (2) the folder parameter in emumail.fcgi, or Javascript in the (3) username or (4) password field in the login page. [email protected] 4.3 0.95% 2004-12-31 2026-04-16
CVE-2002-1527 emumail.cgi in EMU Webmail 5.0 allows remote attackers to determine the full pathname for emumail.cgi via a malformed string containing script, which generates a regular expression matching error that includes the pathname in the resulting error message. [email protected] 5.0 4.31% 2003-04-02 2026-04-16
CVE-2002-1526 Cross-site scripting (XSS) vulnerability in emumail.cgi for EMU Webmail 5.0 allows remote attackers to inject arbitrary HTML or script via the email address field. [email protected] 4.3 0.56% 2003-04-02 2026-04-16
CVE-2002-0532 EMU Webmail allows local users to execute arbitrary programs via a .. (dot dot) in the HTTP Host header that points to a Trojan horse configuration file that contains a pageroot specifier that contains shell metacharacters. [email protected] 7.2 0.05% 2002-08-12 2026-04-16
CVE-2002-0531 Directory traversal vulnerability in emumail.cgi in EMU Webmail 4.5.x and 5.1.0 allows remote attackers to read arbitrary files or list arbitrary directories via a .. (dot dot) in the type parameter. [email protected] 5.0 2.61% 2002-08-12 2026-04-16
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence