lsoft records
10 published records for vendor lsoft.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 5
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
10 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2000-0425Proof of concept | Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.lsoft · listserv | Critical10.0 | — | 5.8% | May 3, 2000 |
32Monitor | CVE-2006-1044No exploit | Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote alsoft · listserv | High7.5 | — | 7.5% | Mar 7, 2006 |
32Monitor | CVE-2022-40319Proof of concept | The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addrelsoft · listserv · CWE-639 | High7.5 | — | 7.2% | Jan 17, 2023 |
31Monitor | CVE-2000-0632No exploit | Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via alsoft · listserv | High7.5 | — | 3.6% | Jul 17, 2000 |
31Monitor | CVE-1999-0252No exploit | Buffer overflow in listserv allows arbitrary command execution.lsoft · listserv | High7.5 | — | 2.9% | Jan 1, 1997 |
31Monitor | CVE-2005-1773No exploit | Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial lsoft · listserv | High7.5 | — | 2.7% | May 31, 2005 |
26Monitor | CVE-2019-15501Proof of concept | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.lsoft · listserv · CWE-79 | Medium6.1 | — | 7.4% | Aug 26, 2019 |
26Monitor | CVE-2022-39195Proof of concept | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML vlsoft · listserv · CWE-79 | Medium6.1 | — | 6.3% | Jan 17, 2023 |
24Monitor | CVE-2023-27641Proof of concept | The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craflsoft · listserv · CWE-79 | Medium6.1 | — | 1.1% | Mar 5, 2023 |
17Monitor | CVE-2010-2723No exploit | Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T paralsoft · listserv · CWE-79 | Medium4.3 | — | 0.8% | Jul 13, 2010 |
- CVE-2000-042542Plan
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
CriticalCVSS 10.0Proof of conceptEPSS 6%lsoft · listservMay 3, 2000
- CVE-2006-104432Monitor
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote a
HighCVSS 7.5No exploitEPSS 7%lsoft · listservMar 7, 2006
- CVE-2022-4031932Monitor
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addre
HighCVSS 7.5Proof of conceptEPSS 7%lsoft · listservJan 17, 2023
- CVE-2000-063231Monitor
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a
HighCVSS 7.5No exploitEPSS 4%lsoft · listservJul 17, 2000
- CVE-1999-025231Monitor
Buffer overflow in listserv allows arbitrary command execution.
HighCVSS 7.5No exploitEPSS 3%lsoft · listservJan 1, 1997
- CVE-2005-177331Monitor
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial
HighCVSS 7.5No exploitEPSS 3%lsoft · listservMay 31, 2005
- CVE-2019-1550126Monitor
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
MediumCVSS 6.1Proof of conceptEPSS 7%lsoft · listservAug 26, 2019
- CVE-2022-3919526Monitor
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML v
MediumCVSS 6.1Proof of conceptEPSS 6%lsoft · listservJan 17, 2023
- CVE-2023-2764124Monitor
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craf
MediumCVSS 6.1Proof of conceptEPSS 1%lsoft · listservMar 5, 2023
- CVE-2010-272317Monitor
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T para
MediumCVSS 4.3No exploitEPSS 1%lsoft · listservJul 13, 2010