netopia records
11 published records for vendor netopia.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 1 · 9.1%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-20 Improper Input Validation2
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
61This week | CVE-2008-1117Weaponized | Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windowsnetopia · timbuktu pro · CWE-22 | Critical10.0 | — | 69.5% | Mar 14, 2008 |
31Monitor | CVE-2008-1118Proof of concept | Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken fronetopia · timbuktu pro · CWE-20 | High7.5 | — | 2.9% | Mar 14, 2008 |
22Monitor | CVE-2000-0142Proof of concept | The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 141netopia · timbuktu pro | Medium5.0 | — | 8.0% | Feb 11, 2000 |
21Monitor | CVE-2002-0135Proof of concept | Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of thnetopia · timbuktu pro | Medium5.0 | — | 3.2% | Mar 25, 2002 |
21Monitor | CVE-2000-1179No exploit | Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the lognetopia · 650-st isdn router | Medium5.0 | — | 2.5% | Jan 9, 2001 |
21Monitor | CVE-2004-0810No exploit | Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data strnetopia · timbuktu pro mac | Medium5.0 | — | 2.0% | Dec 23, 2004 |
21Monitor | CVE-2008-1337No exploit | The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (dnetopia · timbuktu pro · CWE-20 | Medium5.0 | — | 1.7% | Mar 14, 2008 |
20Monitor | CVE-2000-0086No exploit | Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.netopia · timbuktu pro | Medium5.0 | — | 1.4% | Jan 18, 2000 |
20Monitor | CVE-2001-0185No exploit | Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to netopia · r9100 router | Medium5.0 | — | 1.4% | Mar 26, 2001 |
15Monitor | CVE-2000-0379Proof of concept | The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do netopia · r-series routers | Low3.6 | — | 1.8% | May 16, 2000 |
8Monitor | CVE-2001-0438No exploit | Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.netopia · timbuktu mac | Low2.1 | — | 0.3% | Jul 2, 2001 |
- CVE-2008-111761This week
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows
CriticalCVSS 10.0WeaponizedEPSS 69%netopia · timbuktu proMar 14, 2008
- CVE-2008-111831Monitor
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken fro
HighCVSS 7.5Proof of conceptEPSS 3%netopia · timbuktu proMar 14, 2008
- CVE-2000-014222Monitor
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 141
MediumCVSS 5.0Proof of conceptEPSS 8%netopia · timbuktu proFeb 11, 2000
- CVE-2002-013521Monitor
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of th
MediumCVSS 5.0Proof of conceptEPSS 3%netopia · timbuktu proMar 25, 2002
- CVE-2000-117921Monitor
Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the log
MediumCVSS 5.0No exploitEPSS 2%netopia · 650-st isdn routerJan 9, 2001
- CVE-2004-081021Monitor
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data str
MediumCVSS 5.0No exploitEPSS 2%netopia · timbuktu pro macDec 23, 2004
- CVE-2008-133721Monitor
The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (d
MediumCVSS 5.0No exploitEPSS 2%netopia · timbuktu proMar 14, 2008
- CVE-2000-008620Monitor
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.
MediumCVSS 5.0No exploitEPSS 1%netopia · timbuktu proJan 18, 2000
- CVE-2001-018520Monitor
Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to
MediumCVSS 5.0No exploitEPSS 1%netopia · r9100 routerMar 26, 2001
- CVE-2000-037915Monitor
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do
LowCVSS 3.6Proof of conceptEPSS 2%netopia · r-series routersMay 16, 2000
- CVE-2001-04388Monitor
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.
LowCVSS 2.1No exploitEPSS 0%netopia · timbuktu macJul 2, 2001