Eserv

Vendor:

First CVE: Nov 4, 1999 · Active for 26 years

11
Total CVEs
More Total CVEs than 89% of tracked products
1.8
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Eserv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 1999
26 years ago
Most Recent CVE
Oct 15, 2008
6,492 days ago

CVE Severity & Scoring

Eserv11 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown11 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown11 (100.0%)
User Interaction
None0 (0.0%)
Unknown11 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown11 (100.0%)

Top CVEs

Signals from CVEs in this product scope (11 CVEs).

11 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary
Oct 15, 200810.037NOYES
Buffer overflow in the logging feature of EServ 2.9.2 and earlier allows an attacker to execute arbitrary commands via a long MKD command.
Jun 6, 200010.036NOYES
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote attackers to cause a denial of service (crash) via a large amoun
Dec 31, 20035.029NOYES
Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection
Jun 16, 20035.025NOYES
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
Mar 25, 20025.025NOYES
Directory traversal vulnerability in Etype Eserv 2.50 web server allows a remote attacker to read any file in the file system via a .. (dot dot) in a URL.
Nov 4, 19995.025NOYES
Etype Eserv 2.97 allows remote attackers to redirect traffic to other sites (aka FTP bounce) via the PORT command.
May 16, 20027.524NONO
EServ 2.92 Build 2982 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long HELO and MAIL FROM commands.
Dec 19, 20007.520NONO
Etype Eserv 2.97 allows remote attackers to cause a denial of service (resource exhaustion) via a large number of PASV commands that consume ports 1024 through 5000, which prevents
May 16, 20025.019NONO
Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other user's email messages, create/rename arbitrary directories on
Jun 2, 20065.516NONO

Exploit Exposure

Signals from CVEs in this product scope (11 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
54.5% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (11 CVEs).

Media Mentions

Signals from CVEs in this product scope (11 CVEs).

Top CNAs Publishing CVEs For Eserv

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.26110.06.8%01
3.2536.53.4%01
3.036.53.4%01
2.9x15.07.8%01
2.9815.04.0%01
2.9745.63.8%02
2.9625.06.0%02
2.95_beta215.08.1%01
2.9525.06.0%02
2.9425.06.0%02
2.9325.06.0%02
2.9.2110.05.0%01
2.9235.84.7%02
2.5015.08.3%01