Nocc is a narrowly scoped webmail application whose vulnerabilities concentrate in input-handling and content-generation issues, particularly cross-site scripting flaws arising from inadequate neutralization during page rendering. The vendor's disclosed flaws have frequently acquired public exploit code, making this a product where proof-of-concept tooling is readily available. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nocc over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0891MEDIUM Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) | Feb 25, 2006 | 5.0 | 25 | NO | YES |
CVE-2006-0894MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in e | Feb 25, 2006 | 4.3 | 21 | NO | YES |
CVE-2002-2343MEDIUM Cross-site scripting (XSS) vulnerability in NOCC 0.9 through 0.9.5 allows remote attackers to inject arbitrary web script or HTML via email messages. | Dec 31, 2002 | 4.3 | 21 | NO | YES |
CVE-2006-0892HIGH NOCC Webmail 1.0 stores e-mail attachments in temporary files with predictable filenames, which makes it easier for remote attackers to execute arbitrary code by accessing the e-ma | Feb 25, 2006 | 7.5 | 20 | NO | NO |
CVE-2006-0893MEDIUM NOCC Webmail 1.0 allows remote attackers to obtain sensitive information via a direct request to (1) the profiles directory, which leaks e-mail addresses contained in filenames of | Feb 25, 2006 | 5.0 | 15 | NO | NO |
CVE-2006-0895MEDIUM NOCC Webmail 1.0 allows remote attackers to obtain the installation path via a direct request to html/header.php. | Feb 25, 2006 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nocc.
Media articles that mention a CVE ID that affects a product developed by Nocc — matched by CVE ID, not by vendor name.