Перейти к содержимому
Noroxi

Записи lsoft

10 опубликованных записей вендора lsoft.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
5
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 19
  2. 23

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

10 записей
  • CVE-2000-0425
    42В плане

    Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.

    КритическаяCVSS 10,0Proof of conceptEPSS 6 %

    lsoft · listserv3 мая 2000 г.

  • CVE-2006-1044
    32Наблюдать

    Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 7 %

    lsoft · listserv7 мар. 2006 г.

  • CVE-2022-40319
    32Наблюдать

    The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email addre

    ВысокаяCVSS 7,5Proof of conceptEPSS 7 %

    lsoft · listserv17 янв. 2023 г.

  • CVE-2000-0632
    31Наблюдать

    Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %

    lsoft · listserv17 июл. 2000 г.

  • CVE-1999-0252
    31Наблюдать

    Buffer overflow in listserv allows arbitrary command execution.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    lsoft · listserv1 янв. 1997 г.

  • CVE-2005-1773
    31Наблюдать

    Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    lsoft · listserv31 мая 2005 г.

  • CVE-2019-15501
    26Наблюдать

    Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.

    СредняяCVSS 6,1Proof of conceptEPSS 7 %

    lsoft · listserv26 авг. 2019 г.

  • CVE-2022-39195
    26Наблюдать

    A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML v

    СредняяCVSS 6,1Proof of conceptEPSS 6 %

    lsoft · listserv17 янв. 2023 г.

  • CVE-2023-27641
    24Наблюдать

    The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a craf

    СредняяCVSS 6,1Proof of conceptEPSS 1 %

    lsoft · listserv5 мар. 2023 г.

  • CVE-2010-2723
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T para

    СредняяCVSS 4,3Эксплойта нетEPSS 1 %

    lsoft · listserv13 июл. 2010 г.