Listserv
Vendor:
First CVE: Jan 1, 1997 · Active for 29 years
10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Listserv over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
Mar 5, 2023
1,238 days ago
CVE Severity & Scoring
Listserv10 CVEs
40%
60%
All CVEs352,708 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None1 (10.0%)
Unknown6 (60.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (40.0%)
Unknown6 (60.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-39195MEDIUM A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter. | Jan 17, 2023 | 6.1 | 42 | NO | YES |
CVE-2019-15501MEDIUM Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter. | Aug 26, 2019 | 6.1 | 42 | NO | YES |
CVE-2022-40319HIGH The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauth | Jan 17, 2023 | 7.5 | 37 | NO | YES |
CVE-2000-0425HIGH Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands. | May 3, 2000 | 10.0 | 37 | NO | YES |
CVE-2023-27641MEDIUM The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL. | Mar 5, 2023 | 6.1 | 30 | NO | YES |
CVE-2006-1044HIGH Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via u | Mar 7, 2006 | 7.5 | 23 | NO | NO |
CVE-2005-1773HIGH Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be | May 31, 2005 | 7.5 | 20 | NO | NO |
CVE-2000-0632HIGH Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string. | Jul 17, 2000 | 7.5 | 20 | NO | NO |
CVE-1999-0252HIGH Buffer overflow in listserv allows arbitrary command execution. | Jan 1, 1997 | 7.5 | 20 | NO | NO |
CVE-2010-2723MEDIUM Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this inf | Jul 13, 2010 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
30.0% of CVEs· 98th percentile
ExploitDB
4 CVEs
40.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Listserv
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.8e | 1 | 7.5 | 2.7% | 0 | 0 |
| 1.8d | 2 | 7.5 | 3.1% | 0 | 0 |
| 1.8c | 1 | 7.5 | 3.6% | 0 | 0 |
| 1.8 | 1 | 10.0 | 5.8% | 0 | 1 |
| 17.0 | 2 | 6.8 | 6.8% | 0 | 2 |
| 16.0 | 1 | 4.3 | 0.9% | 0 | 0 |
| 15.0 | 1 | 4.3 | 0.9% | 0 | 0 |
| 14.4 | 1 | 7.5 | 7.5% | 0 | 0 |
| 14.3 | 2 | 7.5 | 5.1% | 0 | 0 |