Listserv

Vendor:

First CVE: Jan 1, 1997 · Active for 29 years

10
Total CVEs
More Total CVEs than 88% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 56% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Listserv over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 1, 1997
29 years ago
Most Recent CVE
Mar 5, 2023
1,238 days ago

CVE Severity & Scoring

Listserv10 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (40.0%)
Unknown6 (60.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (40.0%)
High0 (0.0%)
Unknown6 (60.0%)
User Interaction
None1 (10.0%)
Unknown6 (60.0%)
Required3 (30.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (40.0%)
Unknown6 (60.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary JavaScript or HTML via the c parameter.
Jan 17, 20236.142NOYES
Reflected cross site scripting (XSS) in L-Soft LISTSERV before 16.5-2018a exists via the /scripts/wa.exe OK parameter.
Aug 26, 20196.142NOYES
The LISTSERV 17 web interface allows remote attackers to conduct Insecure Direct Object References (IDOR) attacks via a modified email address in a wa.exe URL. The impact is unauth
Jan 17, 20237.537NOYES
Buffer overflow in the Web Archives component of L-Soft LISTSERV 1.8 allows remote attackers to execute arbitrary commands.
May 3, 200010.037NOYES
The REPORT (after z but before a) parameter in wa.exe in L-Soft LISTSERV 16.5 before 17 allows an attacker to conduct XSS attacks via a crafted URL.
Mar 5, 20236.130NOYES
Multiple buffer overflows in LISTSERV 14.3 and 14.4, including LISTSERV Lite and HPO, with the web archive interface enabled, allow remote attackers to execute arbitrary code via u
Mar 7, 20067.523NONO
Multiple unknown vulnerabilities in L-Soft LISTSERV 14.3, 1.8e, and 1.8d allow remote attackers to execute arbitrary code or cause a denial of service. NOTE: this candidate may be
May 31, 20057.520NONO
Buffer overflow in the web archive component of L-Soft Listserv 1.8d and earlier allows remote attackers to execute arbitrary commands via a long query string.
Jul 17, 20007.520NONO
Buffer overflow in listserv allows arbitrary command execution.
Jan 1, 19977.520NONO
Cross-site scripting (XSS) vulnerability in LISTSERV 15 and 16 allows remote attackers to inject arbitrary web script or HTML via the T parameter. NOTE: the provenance of this inf
Jul 13, 20104.315NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
3 CVEs
30.0% of CVEs· 98th percentile
ExploitDB
4 CVEs
40.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Listserv

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.8e17.52.7%00
1.8d27.53.1%00
1.8c17.53.6%00
1.8110.05.8%01
17.026.86.8%02
16.014.30.9%00
15.014.30.9%00
14.417.57.5%00
14.327.55.1%00