Записи lsoft
10 опубликованных записей вендора lsoft.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-639 Authorization Bypass Through User-Controlled Key1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
10 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2000-0425Proof of concept | Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.lsoft · listserv | Критическая10,0 | — | 5,8 % | 3 мая 2000 г. |
32Наблюдать | CVE-2006-1044Эксплойта нет | Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote alsoft · listserv | Высокая7,5 | — | 7,5 % | 7 мар. 2006 г. |
32Наблюдать | CVE-2022-40319Proof of concept | The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addrelsoft · listserv · CWE-639 | Высокая7,5 | — | 7,2 % | 17 янв. 2023 г. |
31Наблюдать | CVE-2000-0632Эксплойта нет | Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via alsoft · listserv | Высокая7,5 | — | 3,6 % | 17 июл. 2000 г. |
31Наблюдать | CVE-1999-0252Эксплойта нет | Buffer overflow in listserv allows arbitrary command execution.lsoft · listserv | Высокая7,5 | — | 2,9 % | 1 янв. 1997 г. |
31Наблюдать | CVE-2005-1773Эксплойта нет | Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial lsoft · listserv | Высокая7,5 | — | 2,7 % | 31 мая 2005 г. |
26Наблюдать | CVE-2019-15501Proof of concept | Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.lsoft · listserv · CWE-79 | Средняя6,1 | — | 7,4 % | 26 авг. 2019 г. |
26Наблюдать | CVE-2022-39195Proof of concept | A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML vlsoft · listserv · CWE-79 | Средняя6,1 | — | 6,3 % | 17 янв. 2023 г. |
24Наблюдать | CVE-2023-27641Proof of concept | The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craflsoft · listserv · CWE-79 | Средняя6,1 | — | 1,1 % | 5 мар. 2023 г. |
17Наблюдать | CVE-2010-2723Эксплойта нет | Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T paralsoft · listserv · CWE-79 | Средняя4,3 | — | 0,8 % | 13 июл. 2010 г. |
- CVE-2000-042542В плане
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
КритическаяCVSS 10,0Proof of conceptEPSS 6 %lsoft · listserv3 мая 2000 г.
- CVE-2006-104432Наблюдать
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote a
ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %lsoft · listserv7 мар. 2006 г.
- CVE-2022-4031932Наблюдать
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addre
ВысокаяCVSS 7,5Proof of conceptEPSS 7 %lsoft · listserv17 янв. 2023 г.
- CVE-2000-063231Наблюдать
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %lsoft · listserv17 июл. 2000 г.
- CVE-1999-025231Наблюдать
Buffer overflow in listserv allows arbitrary command execution.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lsoft · listserv1 янв. 1997 г.
- CVE-2005-177331Наблюдать
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %lsoft · listserv31 мая 2005 г.
- CVE-2019-1550126Наблюдать
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
СредняяCVSS 6,1Proof of conceptEPSS 7 %lsoft · listserv26 авг. 2019 г.
- CVE-2022-3919526Наблюдать
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML v
СредняяCVSS 6,1Proof of conceptEPSS 6 %lsoft · listserv17 янв. 2023 г.
- CVE-2023-2764124Наблюдать
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craf
СредняяCVSS 6,1Proof of conceptEPSS 1 %lsoft · listserv5 мар. 2023 г.
- CVE-2010-272317Наблюдать
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T para
СредняяCVSS 4,3Эксплойта нетEPSS 1 %lsoft · listserv13 июл. 2010 г.