Page 2 of 10 results (0.022 seconds)

CVSS: 10.0EPSS: 93%CPEs: 50EXPL: 1

Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive. Múltiples desbordamientos de búfer basados en la pila en la función get_header de header.c de LHA 1.14 utilizado en productos como Barracuda Spam Firewall, permite a atacantes remotos o a usuarios locales ejecutar código arbitrario mediante nombres de fichero o de directorio largos en un archivo LHA, lo que dispara el desbordamiento cuando se prueba o se extrae un fichero. • http://archives.neohapsis.com/archives/bugtraq/2006-04/0059.html http://distro.conectiva.com.br/atualizacoes/?id=a&anuncio=000840 http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020776.html http://lists.grok.org.uk/pipermail/full-disclosure/2004-May/020778.html http://marc.info/?l=bugtraq&m=108422737918885&w=2 http://secunia.com/advisories/19514 http://security.gentoo.org/glsa/glsa-200405-02.xml http://securitytracker.com/id?1015866 http://www.debian.org/securi • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 0%CPEs: 10EXPL: 0

Clearswift MAILsweeper 4.0 through 4.3.7 allows remote attackers to bypass filtering via a file attachment that contains "multiple extensions combined with large blocks of white space." • http://www.clearswift.com/download/bin/Patches/ReadMe_SMTP_438.htm http://www.securityfocus.com/bid/7568 • CWE-20: Improper Input Validation •

CVSS: 7.5EPSS: 0%CPEs: 12EXPL: 0

MAILsweeper for SMTP 4.3 allows remote attackers to bypass virus protection via a mail message with a malformed zip attachment, as exploited by certain MIMAIL virus variants. • http://secunia.com/advisories/10148 http://www.computerworld.co.nz/cw.nsf/0/BF9E8E6E2D313E5FCC256DD70016473F?OpenDocument&More= http://www.osvdb.org/2772 http://www.securityfocus.com/bid/8982 https://exchange.xforce.ibmcloud.com/vulnerabilities/13611 •

CVSS: 7.8EPSS: 1%CPEs: 3EXPL: 0

MAILsweeper for SMTP 4.3.6 and 4.3.7 allows remote attackers to cause a denial of service (CPU consumption) via a PowerPoint attachment that either (1) is corrupt or (2) contains "embedded objects." • http://www.clearswift.com/download/bin/Patches/ReadMe_SMTP_438.htm http://www.securityfocus.com/bid/7562 https://exchange.xforce.ibmcloud.com/vulnerabilities/12052 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 5.0EPSS: 0%CPEs: 2EXPL: 0

Clearswift MAILsweeper for SMTP 4.3.6 SP1 does not execute custom "on strip unsuccessful" hooks, which allows remote attackers to bypass e-mail attachment filtering policies via an attachment that MAILsweeper can detect but not remove. • http://www.mimesweeper.com/download/bin/Patches/MAILsweeper_Patches_301_ReadMe.htm http://www.securityfocus.com/bid/7226 https://exchange.xforce.ibmcloud.com/vulnerabilities/11745 •