← Vulnerability feed

Vulnerability record · CVE-2004-1312 · published 3 January 2005

CVE-2004-1312: Gfi mailessentials vulnerability

Gfi · Mailessentials

A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.

10.0 CVSS 2.0 High EPSS 2.5% · top 16.1%
10.0CVSS 2.0 base score
2.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

A bug in the HTML parser in a certain Microsoft HTML library, as used in various third party products, may allow remote attackers to cause a denial of service via certain strings, as reported in GFI MailEssentials for Exchange 9 and 10, and GFI MailSecurity for Exchange 8, which causes emails to remain in IIS or Exchange mail queues.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-1312 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2025-34491Gfi mailessentials deserialization of untrusted data vulnerabilityGFI MailEssentials prior to version 21.8 is vulnerable to a .NET deserialization issue. A remote and authenticated attacker can execute arbitrary cod…EPSS 0.95%7.8CVE-2025-34489Gfi mailessentials deserialization of untrusted data vulnerabilityGFI MailEssentials prior to version 21.8 is vulnerable to a local privilege escalation issue. A local attacker can escalate to NT Authority/SYSTEM by…EPSS 0.33%7.5CVE-2005-3182Gfi mailsecurity vulnerabilityBuffer overflow in the HTTP management interface for GFI MailSecurity 8.1 allows remote attackers to execute arbitrary code via long headers such as …EPSS 4.0%7.5CVE-2002-1121Gfi mailsecurity vulnerabilitySMTP content filter engines, including (1) GFI MailSecurity for Exchange/SMTP before 7.2, (2) InterScan VirusWall before 3.52 build 1494, (3) the def…EPSS 6.7%6.5CVE-2025-34490Gfi mailessentials xml external entity (xxe) vulnerabilityGFI MailEssentials prior to version 21.8 is vulnerable to an XML External Entity (XXE) issue. An authenticated and remote attacker can send crafted H…EPSS 0.72%5.3CVE-2026-23621Gfi mailessentials observable discrepancy vulnerabilityGFI MailEssentials AI versions prior to 22.4 contain an arbitrary directory existence enumeration vulnerability in the ListServer.IsPathExist() web m…EPSS 0.25%5.3CVE-2026-23620Gfi mailessentials observable discrepancy vulnerabilityGFI MailEssentials AI versions prior to 22.4 contain an arbitrary file existence enumeration vulnerability in the ListServer.IsDBExist() web method e…EPSS 0.19%5.1CVE-2026-23616Gfi mailessentials cross-site scripting vulnerabilityGFI MailEssentials AI versions prior to 22.4 contain a stored cross-site scripting vulnerability in the Anti-Spoofing configuration page. An authenti…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2004-1312), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.