cbcvebase.

Etype Eserv vulnerabilities

11 known vulnerabilities affecting etype/eserv.

Total CVEs
11
CISA KEV
0
Public exploits
6
Exploited in wild
0
Severity breakdown
CRITICAL2HIGH2MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2008-4588P3CRITICALCVSS 10.0PoCv3.0v3.25+1 more2008-10-15
CVE-2008-4588 [CRITICAL] CWE-119 CVE-2008-4588: Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attac Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via a long argument to the ABOR command.
nvd
CVE-2000-0523P4CRITICALCVSS 10.0PoCv2.9.22000-06-06
CVE-2000-0523 [CRITICAL] CVE-2000-0523: Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbi Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.
nvd
CVE-2002-0112P4MEDIUMCVSS 5.0PoCv2.92v2.93+5 more2002-03-25
CVE-2002-0112 [MEDIUM] CVE-2002-0112: Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL. Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
nvd
CVE-1999-1509P4MEDIUMCVSS 5.0PoCv2.501999-11-04
CVE-1999-1509 [MEDIUM] CVE-1999-1509: Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read an Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.
nvd
CVE-2003-0290P4MEDIUMCVSS 5.0PoCv2.9x2003-06-16
CVE-2003-0290 [MEDIUM] CVE-2003-0290: Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) v Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.
nvd
CVE-2003-1266P4MEDIUMCVSS 5.0PoCv2.92v2.93+5 more2003-12-31
CVE-2003-1266 [MEDIUM] CVE-2003-1266: The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.9 The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amount of data.
nvd
CVE-2006-2308P4MEDIUMCVSS 5.5v3.0v3.252006-06-02
CVE-2006-2308 [MEDIUM] CVE-2006-2308: Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated us Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on the system, and delete empty directories via directory traversal sequences in the (1) CREATE, (2) SELECT, (3) DELETE, (4) RENAME, (5) COPY or (6) APPEND commands.
nvd
CVE-2002-0222P4HIGHCVSS 7.5v2.972002-05-16
CVE-2002-0222 [HIGH] CVE-2002-0222: Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
nvd
CVE-2000-0907P4HIGHCVSS 7.5v2.922000-12-19
CVE-2000-0907 [HIGH] CVE-2000-0907: EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbi EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.
nvd
CVE-2006-2309P4MEDIUMCVSS 4.0v3.0v3.252006-06-02
CVE-2006-2309 [MEDIUM] CVE-2006-2309: The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests containing dot, space, and slash characters, which reveals the source code of script files.
nvd
CVE-2002-0221P4MEDIUMCVSS 5.0v2.972002-05-16
CVE-2002-0221 [MEDIUM] CVE-2002-0221: Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a la Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents the server from accepting valid PASV.
nvd
Etype Eserv vulnerabilities | cvebase