Gfi Mailessentials vulnerabilities
22 known vulnerabilities affecting gfi/mailessentials.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM19
Vulnerabilities
Page 2 of 2
CVE-2025-34490MEDIUMCVSS 6.5fixed in 21.82025-04-28
CVE-2025-34490 [MEDIUM] CWE-611 CVE-2025-34490: GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An aut
GFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted HTTP requests to read arbitrary system files.
cvelistv5nvd
CVE-2004-1312CRITICALCVSS 10.0v9.0v10.0+1 more2005-01-03
CVE-2004-1312 [CRITICAL] CVE-2004-1312: A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party product
A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.
nvd
← Previous2 / 2