Skip to content
Noroxi

lsoft records

10 published records for vendor lsoft.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
5
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 19
  2. 23

Bar: total · dark part: CISA KEV.

All records

10 records
  • Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.

    CriticalCVSS 10.0Proof of conceptEPSS 6%

    lsoft · listservMay 3, 2000

  • CVE-2006-1044
    32Monitor

    Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote a

    HighCVSS 7.5No exploitEPSS 7%

    lsoft · listservMar 7, 2006

  • The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addre

    HighCVSS 7.5Proof of conceptEPSS 7%

    lsoft · listservJan 17, 2023

  • CVE-2000-0632
    31Monitor

    Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a

    HighCVSS 7.5No exploitEPSS 4%

    lsoft · listservJul 17, 2000

  • CVE-1999-0252
    31Monitor

    Buffer overflow in listserv allows arbitrary command execution.

    HighCVSS 7.5No exploitEPSS 3%

    lsoft · listservJan 1, 1997

  • CVE-2005-1773
    31Monitor

    Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial

    HighCVSS 7.5No exploitEPSS 3%

    lsoft · listservMay 31, 2005

  • Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

    MediumCVSS 6.1Proof of conceptEPSS 7%

    lsoft · listservAug 26, 2019

  • A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML v

    MediumCVSS 6.1Proof of conceptEPSS 6%

    lsoft · listservJan 17, 2023

  • The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craf

    MediumCVSS 6.1Proof of conceptEPSS 1%

    lsoft · listservMar 5, 2023

  • CVE-2010-2723
    17Monitor

    Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T para

    MediumCVSS 4.3No exploitEPSS 1%

    lsoft · listservJul 13, 2010