Vulnerabilities (CVE)

Filtered by vendor Imp Subscribe
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2000-0459 1 Imp 1 Imp 2023-12-10 5.0 MEDIUM N/A
IMP does not remove files properly if the MSWordView application quits, which allows local users to cause a denial of service by filling up the disk space by requesting a large number of documents and prematurely stopping the request.
CVE-2001-0857 1 Imp 1 Webmail 2023-12-10 7.5 HIGH N/A
Cross-site scripting vulnerability in status.php3 in Imp Webmail 2.2.6 and earlier allows remote attackers to gain access to the e-mail of other users by hijacking session cookies via the message parameter.
CVE-2000-0458 1 Imp 1 Imp 2023-12-10 2.1 LOW N/A
The MSWordView application in IMP creates world-readable files in the /tmp directory, which allows other local users to read potentially sensitive information.