nocc records
6 published records for vendor nocc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Attack profile
All records
6 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-0892No exploit | NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execnocc · nocc | High7.5 | — | 3.9% | Feb 25, 2006 |
23Monitor | CVE-2006-0891Proof of concept | Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via ..nocc · nocc | Medium5.0 | — | 8.5% | Feb 25, 2006 |
21Monitor | CVE-2006-0893No exploit | NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mnocc · nocc | Medium5.0 | — | 1.8% | Feb 25, 2006 |
21Monitor | CVE-2006-0895No exploit | NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.nocc · nocc | Medium5.0 | — | 1.7% | Feb 25, 2006 |
18Monitor | CVE-2006-0894Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1nocc · nocc | Medium4.3 | — | 2.7% | Feb 25, 2006 |
17Monitor | CVE-2002-2343Proof of concept | Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email nocc · nocc · CWE-79 | Medium4.3 | — | 1.6% | Dec 31, 2002 |
- CVE-2006-089231Monitor
NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to exec
HighCVSS 7.5No exploitEPSS 4%nocc · noccFeb 25, 2006
- CVE-2006-089123Monitor
Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via ..
MediumCVSS 5.0Proof of conceptEPSS 8%nocc · noccFeb 25, 2006
- CVE-2006-089321Monitor
NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-m
MediumCVSS 5.0No exploitEPSS 2%nocc · noccFeb 25, 2006
- CVE-2006-089521Monitor
NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php.
MediumCVSS 5.0No exploitEPSS 2%nocc · noccFeb 25, 2006
- CVE-2006-089418Monitor
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1
MediumCVSS 4.3Proof of conceptEPSS 3%nocc · noccFeb 25, 2006
- CVE-2002-234317Monitor
Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email
MediumCVSS 4.3Proof of conceptEPSS 2%nocc · noccDec 31, 2002