Software602 develops a modestly sized portfolio of network and groupware infrastructure products, including its LAN suite and groupware server, that operate in moderately visible deployment contexts. The vendor's vulnerability disclosures cluster around memory-safety and bounds-checking weaknesses characteristic of legacy infrastructure software, and the exposure has a tendency to acquire public exploit code. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Software602 over time
Signals from CVEs in this vendor scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-5409HIGH Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGuard Internet Security 8.5, and (3) Software602 Groupware Ser | Dec 10, 2008 | 9.3 | 38 | NO | YES |
CVE-2004-0337MEDIUM Cross-site scripting (XSS) vulnerability in LAN SUITE Web Mail 602Pro allows remote attackers to execute arbitrary script or HTML as other users via a URL to index.html, followed b | Nov 23, 2004 | 6.8 | 32 | NO | YES |
CVE-2005-1423MEDIUM Directory traversal vulnerability in the mail program in 602LAN SUITE 2004.0.05.0413 allows remote attackers to cause a denial of service and determine the presence of arbitrary fi | May 3, 2005 | 6.4 | 26 | NO | YES |
CVE-2002-2152HIGH The Czech edition of Software602's Web Server before 2002.0.02.0916 allows remote attackers to gain administrator privileges via direct HTTP requests to the /admin/ directory, whic | Dec 31, 2002 | 10.0 | 25 | NO | NO |
CVE-2005-0344MEDIUM Directory traversal vulnerability in 602LAN SUITE 2004.0.04.1221 allows remote authenticated users to upload and execute arbitrary files via a .. (dot dot) in the filename paramete | May 2, 2005 | 5.0 | 23 | NO | YES |
CVE-2002-2174MEDIUM The Telnet proxy of 602Pro LAN SUITE 2002 does not restrict the number of outstanding connections to the local host, which allows remote attackers to create a denial of service (me | Dec 31, 2002 | 5.0 | 23 | NO | YES |
CVE-2007-3203HIGH Stack-based buffer overflow in smtpdll.dll in the SMTP service in 602Pro LAN SUITE 2003 2003.0.03.0828 allows remote attackers to execute arbitrary code via an e-mail message with | Jun 12, 2007 | 7.5 | 20 | NO | NO |
CVE-2001-0447HIGH Web configuration server in 602Pro LAN SUITE allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long HTTP request containing "%2e" | Jun 18, 2001 | 7.5 | 20 | NO | NO |
CVE-2000-1115HIGH Buffer overflow in remote web administration component (webprox.dll) of 602Pro LAN SUITE before 2000.0.1.33 allows remote attackers to cause a denial of service and possibly execut | Jan 9, 2001 | 7.5 | 20 | NO | NO |
CVE-2004-1501MEDIUM The webmail service in 602 Lan Suite 2004.0.04.0909 and earlier allows remote attackers to cause a denial of service (CPU and memory consumption) by sending a POST request with a l | Dec 31, 2004 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (16 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Software602.
Media articles that mention a CVE ID that affects a product developed by Software602 — matched by CVE ID, not by vendor name.