NetWin kayıtları
netwin üreticisine ait 50 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 11
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer7
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')5
- CWE-134 Use of Externally-Controlled Format String2
- CWE-399 Resource Management Errors1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
50 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2000-0490Kavram kanıtı | Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN rnetwin · dmail | Kritik10,0 | — | %6,2 | 1 Haz 2000 |
41Planlayın | CVE-2001-1356İstismar yok | NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote anetwin · surgeftp | Kritik10,0 | — | %3,8 | 4 Ağu 2001 |
41Planlayın | CVE-2001-1355İstismar yok | Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages, netwin · dmail | Kritik10,0 | — | %3,6 | 20 Tem 2001 |
41Planlayın | CVE-2004-2537İstismar yok | Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."netwin · surgemail | Kritik10,0 | — | %1,7 | 31 Ara 2004 |
40Planlayın | CVE-2007-4372İstismar yok | Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.netwin · surgemail | Kritik10,0 | — | %1,2 | 16 Ağu 2007 |
38İzleyin | CVE-2008-1498Kavram kanıtı | Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitranetwin · surgemail · CWE-119 | Kritik9,0 | — | %7,6 | 25 Mar 2008 |
38İzleyin | CVE-2008-1497İstismar yok | Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrarnetwin · surgemail · CWE-119 | Kritik9,0 | — | %6,3 | 25 Mar 2008 |
34İzleyin | CVE-2007-3768İstismar yok | The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed responetwin · surgeftp | Yüksek8,5 | — | %1,6 | 15 Tem 2007 |
33İzleyin | CVE-2004-2254Kavram kanıtı | SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration netwin · surgeldap | Yüksek7,5 | — | %8,4 | 31 Ara 2004 |
32İzleyin | CVE-2008-1055Kavram kanıtı | Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote atnetwin · surgemail · CWE-134 | Yüksek7,5 | — | %7,9 | 27 Şub 2008 |
31İzleyin | CVE-2005-1478İstismar yok | Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifiernetwin · dmail | Yüksek7,5 | — | %4,8 | 11 May 2005 |
31İzleyin | CVE-2013-4742İstismar yok | Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary conetwin · surgeftp · CWE-119 | Yüksek7,5 | — | %4,3 | 9 Ağu 2013 |
31İzleyin | CVE-2007-2655İstismar yok | Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a formatnetwin · surgemail · CWE-134 | Yüksek7,5 | — | %3,9 | 14 May 2007 |
31İzleyin | CVE-2006-5100Kavram kanıtı | PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arnetwin · webnews | Yüksek7,5 | — | %3,8 | 3 Eki 2006 |
31İzleyin | CVE-2002-0290İstismar yok | Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.netwin · webnews | Yüksek7,5 | — | %3,3 | 31 May 2002 |
31İzleyin | CVE-2000-0422İstismar yok | Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.netwin · dmail | Yüksek7,5 | — | %2,0 | 4 May 2000 |
30İzleyin | CVE-2005-1516İstismar yok | DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog commnetwin · dmail | Yüksek7,5 | — | %1,6 | 11 May 2005 |
30İzleyin | CVE-2002-0310İstismar yok | Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whicnetwin · webnews | Yüksek7,5 | — | %1,6 | 31 May 2002 |
27İzleyin | CVE-2008-1054Kavram kanıtı | Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earlnetwin · surgemail · CWE-119 | Orta6,4 | — | %7,4 | 27 Şub 2008 |
27İzleyin | CVE-2008-1052Kavram kanıtı | The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vinetwin · surgeftp · CWE-119 | Orta6,4 | — | %6,8 | 27 Şub 2008 |
26İzleyin | CVE-2007-4377Kavram kanıtı | Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argunetwin · surgemail | Orta6,0 | — | %5,0 | 16 Ağu 2007 |
24İzleyin | CVE-2017-17933İstismar yok | cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainnetwin · surgeftp · CWE-79 | Orta6,1 | — | %0,9 | 29 Ara 2017 |
23İzleyin | CVE-2008-7182Kavram kanıtı | Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users tonetwin · surgemail · CWE-119 | Orta4,0 | — | %24,3 | 8 Eyl 2009 |
23İzleyin | CVE-2007-3769İstismar yok | Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servnetwin · surgeftp | Orta5,8 | — | %1,2 | 15 Tem 2007 |
22İzleyin | CVE-2000-0423Kavram kanıtı | Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,netwin · dnews | Orta5,0 | — | %7,8 | 5 May 2000 |
- CVE-2000-049042Planlayın
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary commands via a long ETRN r
KritikCVSS 10,0Kavram kanıtıEPSS %6netwin · dmail1 Haz 2000
- CVE-2001-135641Planlayın
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote a
KritikCVSS 10,0İstismar yokEPSS %4netwin · surgeftp4 Ağu 2001
- CVE-2001-135541Planlayın
Buffer overflows in NetWin Authentication Module (NWAuth) 3.0b and earlier, as implemented in DMail, SurgeFTP, and possibly other packages,
KritikCVSS 10,0İstismar yokEPSS %4netwin · dmail20 Tem 2001
- CVE-2004-253741Planlayın
Unspecified vulnerability in SurgeMail before 2.2c10 has unknown impact and attack vectors, related to a "Webmail security bug."
KritikCVSS 10,0İstismar yokEPSS %2netwin · surgemail31 Ara 2004
- CVE-2007-437240Planlayın
Unspecified vulnerability in NetWin SurgeMail 38k on Windows Server 2003 has unknown impact and remote attack vectors.
KritikCVSS 10,0İstismar yokEPSS %1netwin · surgemail16 Ağu 2007
- CVE-2008-149838İzleyin
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated users to execute arbitra
KritikCVSS 9,0Kavram kanıtıEPSS %8netwin · surgemail25 Mar 2008
- CVE-2008-149738İzleyin
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrar
KritikCVSS 9,0İstismar yokEPSS %6netwin · surgemail25 Mar 2008
- CVE-2007-376834İzleyin
The mirror mechanism in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to cause a denial of service (restart) via a malformed respo
YüksekCVSS 8,5İstismar yokEPSS %2netwin · surgeftp15 Tem 2007
- CVE-2004-225433İzleyin
SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration
YüksekCVSS 7,5Kavram kanıtıEPSS %8netwin · surgeldap31 Ara 2004
- CVE-2008-105532İzleyin
Format string vulnerability in webmail.exe in NetWin SurgeMail 38k4 and earlier and beta 39a, and WebMail 3.1s and earlier, allows remote at
YüksekCVSS 7,5Kavram kanıtıEPSS %8netwin · surgemail27 Şub 2008
- CVE-2005-147831İzleyin
Format string vulnerability in dSMTP (dsmtp.exe) in DMail 3.1a allows remote attackers to execute arbitrary code via format string specifier
YüksekCVSS 7,5İstismar yokEPSS %5netwin · dmail11 May 2005
- CVE-2013-474231İzleyin
Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary co
YüksekCVSS 7,5İstismar yokEPSS %4netwin · surgeftp9 Ağu 2013
- CVE-2007-265531İzleyin
Unspecified vulnerability in NetWin Webmail 3.1s-1 in SurgeMail before 3.8i2 has unknown impact and remote attack vectors, possibly a format
YüksekCVSS 7,5İstismar yokEPSS %4netwin · surgemail14 May 2007
- CVE-2006-510031İzleyin
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute ar
YüksekCVSS 7,5Kavram kanıtıEPSS %4netwin · webnews3 Eki 2006
- CVE-2002-029031İzleyin
Buffer overflow in Netwin WebNews CGI program 1.1, Webnews.exe, allows remote attackers to execute arbitrary code via a long group argument.
YüksekCVSS 7,5İstismar yokEPSS %3netwin · webnews31 May 2002
- CVE-2000-042231İzleyin
Buffer overflow in Netwin DMailWeb CGI program allows remote attackers to execute arbitrary commands via a long utoken parameter.
YüksekCVSS 7,5İstismar yokEPSS %2netwin · dmail4 May 2000
- CVE-2005-151630İzleyin
DList (dlist.exe) in DMail 3.1a allows remote attackers to bypass authentication, read log files, and shutdown the system via a sendlog comm
YüksekCVSS 7,5İstismar yokEPSS %2netwin · dmail11 May 2005
- CVE-2002-031030İzleyin
Netwin WebNews 1.1k CGI program includes several default usernames and cleartext passwords that cannot be deleted by the administrator, whic
YüksekCVSS 7,5İstismar yokEPSS %2netwin · webnews31 May 2002
- CVE-2008-105427İzleyin
Stack-based buffer overflow in the _lib_spawn_user_getpid function in (1) swatch.exe and (2) surgemail.exe in NetWin SurgeMail 38k4 and earl
OrtaCVSS 6,4Kavram kanıtıEPSS %7netwin · surgemail27 Şub 2008
- CVE-2008-105227İzleyin
The administration web interface in NetWin SurgeFTP 2.3a2 and earlier allows remote attackers to cause a denial of service (daemon crash) vi
OrtaCVSS 6,4Kavram kanıtıEPSS %7netwin · surgeftp27 Şub 2008
- CVE-2007-437726İzleyin
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary code via a long argu
OrtaCVSS 6,0Kavram kanıtıEPSS %5netwin · surgemail16 Ağu 2007
- CVE-2017-1793324İzleyin
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domain
OrtaCVSS 6,1İstismar yokEPSS %1netwin · surgeftp29 Ara 2017
- CVE-2008-718223İzleyin
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote authenticated users to
OrtaCVSS 4,0Kavram kanıtıEPSS %24netwin · surgemail8 Eyl 2009
- CVE-2007-376923İzleyin
Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP serv
OrtaCVSS 5,8İstismar yokEPSS %1netwin · surgeftp15 Tem 2007
- CVE-2000-042322İzleyin
Buffer overflow in Netwin DNEWSWEB CGI program allows remote attackers to execute arbitrary commands via long parameters such as group, cmd,
OrtaCVSS 5,0Kavram kanıtıEPSS %8netwin · dnews5 May 2000