Записи NetWin
50 опубликованных записей вендора netwin.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 11
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-134 Use of Externally-Controlled Format String2
- CWE-399 Resource Management Errors1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
50 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2000-0490Proof of concept | Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN rnetwin · dmail | Критическая10,0 | — | 6,2 % | 1 июн. 2000 г. |
41В плане | CVE-2001-1356Эксплойта нет | NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote anetwin · surgeftp | Критическая10,0 | — | 3,8 % | 4 авг. 2001 г. |
41В плане | CVE-2001-1355Эксплойта нет | Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, netwin · dmail | Критическая10,0 | — | 3,6 % | 20 июл. 2001 г. |
41В плане | CVE-2004-2537Эксплойта нет | Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."netwin · surgemail | Критическая10,0 | — | 1,7 % | 31 дек. 2004 г. |
40В плане | CVE-2007-4372Эксплойта нет | Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.netwin · surgemail | Критическая10,0 | — | 1,2 % | 16 авг. 2007 г. |
38Наблюдать | CVE-2008-1498Proof of concept | Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitranetwin · surgemail · CWE-119 | Критическая9,0 | — | 7,6 % | 25 мар. 2008 г. |
38Наблюдать | CVE-2008-1497Эксплойта нет | Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrarnetwin · surgemail · CWE-119 | Критическая9,0 | — | 6,3 % | 25 мар. 2008 г. |
34Наблюдать | CVE-2007-3768Эксплойта нет | The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed responetwin · surgeftp | Высокая8,5 | — | 1,6 % | 15 июл. 2007 г. |
33Наблюдать | CVE-2004-2254Proof of concept | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration netwin · surgeldap | Высокая7,5 | — | 8,4 % | 31 дек. 2004 г. |
32Наблюдать | CVE-2008-1055Proof of concept | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote atnetwin · surgemail · CWE-134 | Высокая7,5 | — | 7,9 % | 27 февр. 2008 г. |
31Наблюдать | CVE-2005-1478Эксплойта нет | Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiernetwin · dmail | Высокая7,5 | — | 4,8 % | 11 мая 2005 г. |
31Наблюдать | CVE-2013-4742Эксплойта нет | Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary conetwin · surgeftp · CWE-119 | Высокая7,5 | — | 4,3 % | 9 авг. 2013 г. |
31Наблюдать | CVE-2007-2655Эксплойта нет | Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a formatnetwin · surgemail · CWE-134 | Высокая7,5 | — | 3,9 % | 14 мая 2007 г. |
31Наблюдать | CVE-2006-5100Proof of concept | PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arnetwin · webnews | Высокая7,5 | — | 3,8 % | 3 окт. 2006 г. |
31Наблюдать | CVE-2002-0290Эксплойта нет | Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.netwin · webnews | Высокая7,5 | — | 3,3 % | 31 мая 2002 г. |
31Наблюдать | CVE-2000-0422Эксплойта нет | Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.netwin · dmail | Высокая7,5 | — | 2,0 % | 4 мая 2000 г. |
30Наблюдать | CVE-2005-1516Эксплойта нет | DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog commnetwin · dmail | Высокая7,5 | — | 1,6 % | 11 мая 2005 г. |
30Наблюдать | CVE-2002-0310Эксплойта нет | Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whicnetwin · webnews | Высокая7,5 | — | 1,6 % | 31 мая 2002 г. |
27Наблюдать | CVE-2008-1054Proof of concept | Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlnetwin · surgemail · CWE-119 | Средняя6,4 | — | 7,4 % | 27 февр. 2008 г. |
27Наблюдать | CVE-2008-1052Proof of concept | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vinetwin · surgeftp · CWE-119 | Средняя6,4 | — | 6,8 % | 27 февр. 2008 г. |
26Наблюдать | CVE-2007-4377Proof of concept | Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argunetwin · surgemail | Средняя6,0 | — | 5,0 % | 16 авг. 2007 г. |
24Наблюдать | CVE-2017-17933Эксплойта нет | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainnetwin · surgeftp · CWE-79 | Средняя6,1 | — | 0,9 % | 29 дек. 2017 г. |
23Наблюдать | CVE-2008-7182Proof of concept | Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users tonetwin · surgemail · CWE-119 | Средняя4,0 | — | 24,3 % | 8 сент. 2009 г. |
23Наблюдать | CVE-2007-3769Эксплойта нет | Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servnetwin · surgeftp | Средняя5,8 | — | 1,2 % | 15 июл. 2007 г. |
22Наблюдать | CVE-2000-0423Proof of concept | Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,netwin · dnews | Средняя5,0 | — | 7,8 % | 5 мая 2000 г. |
- CVE-2000-049042В плане
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN r
КритическаяCVSS 10,0Proof of conceptEPSS 6 %netwin · dmail1 июн. 2000 г.
- CVE-2001-135641В плане
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote a
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %netwin · surgeftp4 авг. 2001 г.
- CVE-2001-135541В плане
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages,
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %netwin · dmail20 июл. 2001 г.
- CVE-2004-253741В плане
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
КритическаяCVSS 10,0Эксплойта нетEPSS 2 %netwin · surgemail31 дек. 2004 г.
- CVE-2007-437240В плане
Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %netwin · surgemail16 авг. 2007 г.
- CVE-2008-149838Наблюдать
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitra
КритическаяCVSS 9,0Proof of conceptEPSS 8 %netwin · surgemail25 мар. 2008 г.
- CVE-2008-149738Наблюдать
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrar
КритическаяCVSS 9,0Эксплойта нетEPSS 6 %netwin · surgemail25 мар. 2008 г.
- CVE-2007-376834Наблюдать
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed respo
ВысокаяCVSS 8,5Эксплойта нетEPSS 2 %netwin · surgeftp15 июл. 2007 г.
- CVE-2004-225433Наблюдать
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %netwin · surgeldap31 дек. 2004 г.
- CVE-2008-105532Наблюдать
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote at
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %netwin · surgemail27 февр. 2008 г.
- CVE-2005-147831Наблюдать
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifier
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %netwin · dmail11 мая 2005 г.
- CVE-2013-474231Наблюдать
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %netwin · surgeftp9 авг. 2013 г.
- CVE-2007-265531Наблюдать
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %netwin · surgemail14 мая 2007 г.
- CVE-2006-510031Наблюдать
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute ar
ВысокаяCVSS 7,5Proof of conceptEPSS 4 %netwin · webnews3 окт. 2006 г.
- CVE-2002-029031Наблюдать
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %netwin · webnews31 мая 2002 г.
- CVE-2000-042231Наблюдать
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %netwin · dmail4 мая 2000 г.
- CVE-2005-151630Наблюдать
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog comm
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %netwin · dmail11 мая 2005 г.
- CVE-2002-031030Наблюдать
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whic
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %netwin · webnews31 мая 2002 г.
- CVE-2008-105427Наблюдать
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earl
СредняяCVSS 6,4Proof of conceptEPSS 7 %netwin · surgemail27 февр. 2008 г.
- CVE-2008-105227Наблюдать
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vi
СредняяCVSS 6,4Proof of conceptEPSS 7 %netwin · surgeftp27 февр. 2008 г.
- CVE-2007-437726Наблюдать
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argu
СредняяCVSS 6,0Proof of conceptEPSS 5 %netwin · surgemail16 авг. 2007 г.
- CVE-2017-1793324Наблюдать
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domain
СредняяCVSS 6,1Эксплойта нетEPSS 1 %netwin · surgeftp29 дек. 2017 г.
- CVE-2008-718223Наблюдать
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to
СредняяCVSS 4,0Proof of conceptEPSS 24 %netwin · surgemail8 сент. 2009 г.
- CVE-2007-376923Наблюдать
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP serv
СредняяCVSS 5,8Эксплойта нетEPSS 1 %netwin · surgeftp15 июл. 2007 г.
- CVE-2000-042322Наблюдать
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,
СредняяCVSS 5,0Proof of conceptEPSS 8 %netwin · dnews5 мая 2000 г.