Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown
CVE-2018-3815
Disclosure Date: January 08, 2018 (last updated November 26, 2024)
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /Session URI, and interchanges the XML From and To elements.
0
Attacker Value
Unknown
CVE-2008-6704
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Integer overflow in the NET_Compressor::Decompress function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server crash) via a crafted packet with a 0xc1 value that contains no compressed data, which triggers a copy of a large amount of memory.
0
Attacker Value
Unknown
CVE-2008-6702
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (crash) via a long nickname, which triggers an exception.
0
Attacker Value
Unknown
CVE-2008-6703
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the IPureServer::_Recieve function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to execute arbitrary code via a compressed 0x39 packet, which is decompressed by the NET_Compressor::Decompress function.
0
Attacker Value
Unknown
CVE-2008-6705
Disclosure Date: April 10, 2009 (last updated October 04, 2023)
The MultipacketReciever::RecievePacket function in S.T.A.L.K.E.R.: Shadow of Chernobyl 1.0006 and earlier allows remote attackers to cause a denial of service (server termination) via a crafted packet without an expected 0xe0 or 0xe1 value, which triggers the INT3 instruction.
0
Attacker Value
Unknown
CVE-2007-2718
Disclosure Date: May 16, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the WebMail system in Stalker CommuniGate Pro 5.1.8 and earlier, when using Microsoft Internet Explorer, allows remote attackers to inject arbitrary web script or HTML via crafted STYLE tags.
0
Attacker Value
Unknown
CVE-2006-3477
Disclosure Date: July 10, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the POP service in Stalker CommuniGate Pro 5.1c1 and earlier allows remote attackers to cause a denial of service (server crash) via unspecified vectors involving opening an empty inbox.
0
Attacker Value
Unknown
CVE-2006-0468
Disclosure Date: January 30, 2006 (last updated February 22, 2025)
CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.
0
Attacker Value
Unknown
CVE-2005-2861
Disclosure Date: September 08, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in N-Stealth Commercial Edition before 5.8.0.38 and Free Edition before 5.8.1.03 allows remote attackers to inject arbitrary web script or HTML via the Server field in an HTTP response header, which is directly injected into an HTML report.
0
Attacker Value
Unknown
CVE-2005-1007
Disclosure Date: May 02, 2005 (last updated February 22, 2025)
Unknown vulnerability in the LIST functionality in CommuniGate Pro before 4.3c3 allows remote attackers to cause a denial of service (server crash) via certain multipart messages.
0