VendorsSurfControlsuperscout_email_filterall versions
Vulnerabilities

SurfControl SuperScout Email Filter

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2002-1530
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and plaintext passwords via a request to the userlist.asp program, which includes the passwords in a user editing form.
Published 2004-09-01 · Modified
5.01 PoCEPSS 0.059
CVE-2002-2121
SurfControl SuperScout Email filter for SMTP 3.5.1 allows remote attackers to cause a denial of service (crash) via a long SMTP (1) HELO or (2) RCPT TO command, possibly due to a buffer overflow.
Published 2005-08-05 · Modified
5.0EPSS 0.026
CVE-2002-1531
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (crash) via an HTTP request without a Content-Length parameter.
Published 2004-09-01 · Modified
5.0EPSS 0.026
CVE-2002-1532
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to cause a denial of service (resource exhaustion) via a GET request without the terminating /r/n/r/n (CRLF) sequence, which causes the interface to wait for the sequence and blocks other users from accessing it.
Published 2004-09-01 · Modified
5.0EPSS 0.026
CVE-2002-1529
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows remote attackers to insert arbitrary script or HTML via the Reason parameter.
Published 2004-09-01 · Modified
4.31 PoCEPSS 0.036