CVE-2008-0858
CVE-2008-0858 is a high-severity vulnerability in Kerio Kerio Mailserver with a CVSS 2.0 base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-94.
Key facts
- Severity: High (CVSS 2.0 base score 7.5)
- EPSS exploit prediction: 4% (90th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-94
- Affected product: Kerio Kerio Mailserver
- Published:
- Last modified:
Description
Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.
Frequently asked questions
- What is CVE-2008-0858?
- Buffer overflow in the Visnetic anti-virus plugin in Kerio MailServer before 6.5.0 might allow remote attackers to execute arbitrary code via unspecified vectors.
- How severe is CVE-2008-0858?
- CVE-2008-0858 has a CVSS 2.0 base score of 7.5, rated high severity.
- Is CVE-2008-0858 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 4% (90th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2008-0858?
- CVE-2008-0858 primarily affects Kerio Kerio Mailserver. In total, 2 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2008-0858?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2008-0858 published?
- CVE-2008-0858 was published on 2008-02-21 and last updated on 2026-06-16.
References
- http://secunia.com/advisories/29021
- http://www.kerio.com/kms_history.html
- http://www.securityfocus.com/bid/27868
- http://www.securitytracker.com/id?1019428
- http://www.vupen.com/english/advisories/2008/0594
Affected products (2)
- cpe:2.3:a:kerio:kerio_mailserver:*:*:*:*:*:*:*:*
- cpe:2.3:a:visnetic:visnetic_antivirus_plug-in_for_mail_server:*:*:*:*:*:*:*:*
More vulnerabilities in Kerio Kerio Mailserver
- CVE-2008-0860 — Critical (CVSS 10.0): Unspecified vulnerability in the AVG plugin in Kerio MailServer before 6.5.0 has unspecified impact via unknown remote…
- CVE-2007-3993 — Critical (CVSS 10.0): Unspecified vulnerability in the attachment filter in Kerio MailServer before 6.4.1 has unknown impact and remote…
- CVE-2004-2441 — Critical (CVSS 10.0): Unspecified vulnerability in Kerio MailServer before 6.0.3 has unknown impact and unknown remote attack vectors,…
- CVE-2006-1158 — High (CVSS 7.8): Kerio MailServer before 6.1.3 Patch 1 allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2005-1062 — High (CVSS 7.5): The administration protocol for Kerio WinRoute Firewall 6.x up to 6.0.10, Personal Firewall 4.x up to 4.1.2, and…
- CVE-2003-0487 — High (CVSS 7.5): Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and…
All CVEs affecting Kerio Kerio Mailserver →
Other CWE-94 (Code Injection) vulnerabilities
- CVE-2026-93603 — Critical (CVSS 10.0): vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its…
- CVE-2026-92937 — Critical (CVSS 10.0): vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for…
- CVE-2026-62104 — Critical (CVSS 10.0): Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.
- CVE-2026-73456 — Critical (CVSS 10.0): Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface…
- CVE-2026-73453 — Critical (CVSS 10.0): An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary…
- CVE-2026-53710 — Critical (CVSS 10.0): MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the…