CVE-2007-2616
published 2007-05-11CVE-2007-2616: Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute…
PriorityP347critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.00%
92.5th percentile
Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute arbitrary code via a crafted request.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | httpd | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
| novell | netmail | — | — |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat6.1MEDIUM
vendor_apache4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m623-5pqp-69vm: Stack-based buffer overflow in the SSL version of the NMDMC
ghsa_unreviewed·2022-05-01
CVE-2007-2616 [HIGH] GHSA-m623-5pqp-69vm: Stack-based buffer overflow in the SSL version of the NMDMC
Stack-based buffer overflow in the SSL version of the NMDMC.EXE service in Novell NetMail 3.52e FTF2 and probably earlier allows remote attackers to execute arbitrary code via a crafted request.
GHSA
Apache Tomcat XSS In Accept-Language Headers
ghsa·2022-05-01
CVE-2007-1358 [LOW] CWE-79 Apache Tomcat XSS In Accept-Language Headers
Apache Tomcat XSS In Accept-Language Headers
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
Red Hat
mod_autoindex XSS
vendor_redhat·2007-09-13·CVSS 6.1
CVE-2007-4465 [MEDIUM] CWE-79 mod_autoindex XSS
mod_autoindex XSS
Cross-site scripting (XSS) vulnerability in mod_autoindex.c in the Apache HTTP Server before 2.2.6, when the charset on a server-generated page is not defined, allows remote attackers to inject arbitrary web script or HTML via the P parameter using the UTF-7 charset. NOTE: it could be argued that this issue is due to a design limitation of browsers that attempt to perform automatic content type detection.
Statement: This is actually a flaw in browsers that do not derive the response character set as required by RFC 2616. This does not affect the default configuration of Apache httpd in Red Hat products and will only affect customers who have removed the "AddDefaultCharset" directive and are using directory indexes. The Red Hat Product Security has rated this issue as ha
Red Hat
tomcat accept-language xss flaw
vendor_redhat·2007-06-06·CVSS 2.6
CVE-2007-1358 [LOW] CWE-79 tomcat accept-language xss flaw
tomcat accept-language xss flaw
Cross-site scripting (XSS) vulnerability in certain applications using Apache Tomcat 4.0.0 through 4.0.6 and 4.1.0 through 4.1.34 allows remote attackers to inject arbitrary web script or HTML via crafted "Accept-Language headers that do not conform to RFC 2616".
Apache
Apache httpd: CVE-2008-0005
vendor_apache·CVSS 4.3
CVE-2008-0005 [LOW] Apache httpd: CVE-2008-0005
Apache httpd: CVE-2008-0005
A workaround was added in the mod_proxy_ftp module. On sites where mod_proxy_ftp is enabled and a forward proxy is configured, a cross-site scripting attack is possible against Web browsers which do not correctly derive the response character set following the rules in RFC 2616. Reported to security team 2007-12-15 Issue public 2008-01-08 Update 2.0.63 released 2008-01-19 Update 2.2.8 released 2008-01-19 Affects 2.2.6, 2.2.5, 2.2.4, 2.2.3, 2.2.2, 2.2.0, 2.0.61, 2.0.59, 2.0.58, 2.0.55, 2.0.54, 2.0.53, 2.0.52, 2.0.51, 2.0.50, 2.0.49, 2.0.48, 2.0.47, 2.0.46, 2.0.45, 2.0.44, 2.0.43, 2.0.42, 2.0.40, 2.0.39, 2.0.37, 2.0.36, 2.0.35
Severity: low
No detection rules found.
No public exploits indexed.
http://download.novell.com/Download?buildid=Ad2xk29hHTg~http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=532http://osvdb.org/35941http://secunia.com/advisories/25204http://www.securityfocus.com/bid/23916http://www.securitytracker.com/id?1018045http://www.vupen.com/english/advisories/2007/1732https://exchange.xforce.ibmcloud.com/vulnerabilities/34221http://download.novell.com/Download?buildid=Ad2xk29hHTg~http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=532http://osvdb.org/35941http://secunia.com/advisories/25204http://www.securityfocus.com/bid/23916http://www.securitytracker.com/id?1018045http://www.vupen.com/english/advisories/2007/1732https://exchange.xforce.ibmcloud.com/vulnerabilities/34221
2007-05-11
Published