Avaya Modular Messaging Message Storage Server vulnerabilities
15 known vulnerabilities affecting avaya/modular_messaging_message_storage_server.
Total CVEs
15
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH5MEDIUM5LOW2
Vulnerabilities
Page 1 of 1
CVE-2005-4471MEDIUMCVSS 5.0≤ 2.0_sp_4v1.1+1 more2005-12-22
CVE-2005-4471 [MEDIUM] CVE-2005-4471: POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows rem
POP3 service in Avaya Modular Messaging Message Storage Server (MSS) 2.0 SP 4 and earlier allows remote attackers to cause a denial of service (infinite loop) via crafted packets.
nvd
CVE-2004-1235MEDIUMCVSS 6.2PoCv1.1v2.02005-04-14
CVE-2004-1235 [MEDIUM] CVE-2004-1235: Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux ke
Race condition in the (1) load_elf_library and (2) binfmt_aout function calls for uselib in Linux kernel 2.4 through 2.429-rc2 and 2.6 through 2.6.10 allows local users to execute arbitrary code by manipulating the VMA descriptor.
nvd
CVE-2005-0003LOWCVSS 2.1v1.1v2.02005-04-14
CVE-2005-0003 [LOW] CVE-2005-0003: The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly
The 64 bit ELF support in Linux kernel 2.6 before 2.6.10, on 64-bit architectures, does not properly check for overlapping VMA (virtual memory address) allocations, which allows local users to cause a denial of service (system crash) or execute arbitrary code via a crafted ELF or a.out file.
nvd
CVE-2004-1050CRITICALCVSS 10.0PoCvs34002004-12-31
CVE-2004-1050 [CRITICAL] CVE-2004-1050: Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code
Heap-based buffer overflow in Internet Explorer 6 allows remote attackers to execute arbitrary code via long (1) SRC or (2) NAME attributes in IFRAME, FRAME, and EMBED elements, as originally discovered using the mangleme utility, aka "the IFRAME vulnerability" or the "HTML Elements Vulnerability."
nvd
CVE-2004-0842HIGHCVSS 7.5PoCv1.1v2.02004-12-23
CVE-2004-0842 [HIGH] CVE-2004-0842: Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service (application crash from "memory corruption") via certain malformed Cascading Style Sheet (CSS) elements that trigger heap-based buffer overflows, as demonstrated using the "@;/*" string, possibly due to a missing comment terminator that may c
nvd
CVE-2004-0841MEDIUMCVSS 5.0PoCv1.1v2.02004-12-23
CVE-2004-0841 [MEDIUM] CVE-2004-0841: Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events tha
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.show method and use drag-and-drop actions in a popup window, aka "HijackClick 3" and the "Script in Image Tag File Download Vulnerability."
nvd
CVE-2004-1307HIGHCVSS 7.5v1.1v2.02004-12-21
CVE-2004-1307 [HIGH] CVE-2004-1307: Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remot
Integer overflow in the TIFFFetchStripThing function in tif_dirread.c for libtiff 3.6.1 allows remote attackers to execute arbitrary code via a TIFF file with the STRIPOFFSETS flag and a large number of strips, which causes a zero byte buffer to be allocated and leads to a heap-based buffer overflow.
nvd
CVE-2004-0839MEDIUMCVSS 5.0v1.1v2.02004-08-18
CVE-2004-0839 [MEDIUM] CVE-2004-0839: Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attack
Internet Explorer in Windows XP SP2, and other versions including 5.01 and 5.5, allows remote attackers to install arbitrary programs via a web page that uses certain styles and the AnchorClick behavior, popup windows, and drag-and-drop capabilities to drop the program in the local startup folder, as demonstrated by "wottapoop.html".
nvd
CVE-2004-0201CRITICALCVSS 10.0vs34002004-08-06
CVE-2004-0201 [CRITICAL] CVE-2004-0201: Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, M
Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerability than CVE-2003-1041.
nvd
CVE-2004-0212CRITICALCVSS 10.0PoCvs34002004-08-06
CVE-2004-0212 [CRITICAL] CVE-2004-0212: Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 o
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, allows local or remote attackers to execute arbitrary code via a .job file containing long parameters, as demonstrated using Internet Explorer and accessing a .job file on an anonymous share.
nvd
CVE-2004-0205HIGHCVSS 7.2vs34002004-08-06
CVE-2004-0205 [HIGH] CVE-2004-0205: Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arb
Buffer overflow in Microsoft Internet Information Server (IIS) 4.0 allows local users to execute arbitrary code via the redirect function.
nvd
CVE-2004-0495HIGHCVSS 7.2vs34002004-08-06
CVE-2004-0495 [HIGH] CVE-2004-0495: Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or
Multiple unknown vulnerabilities in Linux kernel 2.4 and 2.6 allow local users to gain privileges or access kernel memory, as found by the Sparse source code checking tool.
nvd
CVE-2004-0215MEDIUMCVSS 5.0vs34002004-08-06
CVE-2004-0215 [MEDIUM] CVE-2004-0215: Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash
Microsoft Outlook Express 5.5 and 6 allows attackers to cause a denial of service (application crash) via a malformed e-mail header.
nvd
CVE-2004-0554LOWCVSS 2.1PoCvs34002004-08-06
CVE-2004-0554 [LOW] CVE-2004-0554: Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash),
Linux kernel 2.4.x and 2.6.x for x86 allows local users to cause a denial of service (system crash), possibly via an infinite loop that triggers a signal handler with a certain sequence of fsave and frstor instructions, as originally demonstrated using a "crash.c" program.
nvd
CVE-2004-1082HIGHCVSS 7.5v1.1v2.02004-02-03
CVE-2004-1082 [HIGH] CVE-2004-1082: mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce
mod_digest_apple for Apache 1.3.31 and 1.3.32 on Mac OS X Server does not properly verify the nonce of a client response, which allows remote attackers to replay credentials.
nvd