Products: 1
    Vulnerabilities: 14
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    11
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2020-13866

    WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Last Modified: Nov 21, 2024
    Published: Jun 08, 2020

    CVE-2009-0802

    Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls for Flash, Java, Silverlight, and probably other technologies, and possibly communicate with restricted intranet sites, via a crafted web page that causes a client to send HTTP requests with a modified Host header.

    Last Modified: Apr 23, 2026
    Published: Mar 04, 2009

    CVE-2008-3606

    Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possibly execute arbitrary code via a long argument to the LIST command. NOTE: some of these details are obtained from third party information.

    Last Modified: Apr 23, 2026
    Published: Aug 12, 2008

    CVE-2007-4335

    Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format string specifiers in certain unexpected commands, which trigger a crash during error logging.

    Last Modified: Apr 23, 2026
    Published: Aug 14, 2007

    CVE-2006-4518

    Qbik WinGate 6.1.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a DNS request with a self-referencing compressed name pointer, which triggers an infinite loop.

    Last Modified: Apr 23, 2026
    Published: Nov 28, 2006
    Items Per Page
    Qbik Vulnerabilities & Security CVEs | CVE-DB