VYPR

Timbuktu Pro

by Netopia

CVEs (8)

  • CVE-2008-1117Mar 14, 2008
    risk 0.09cvss epss 0.69

    Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \…

  • CVE-2000-0142Feb 11, 2000
    risk 0.04cvss epss 0.08

    The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.

  • CVE-2008-1118Mar 14, 2008
    risk 0.03cvss epss 0.03

    Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via…

  • CVE-2002-0135Mar 25, 2002
    risk 0.03cvss epss 0.03

    Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).

  • CVE-2008-1337Mar 14, 2008
    risk 0.00cvss epss 0.02

    The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial…

  • CVE-2004-0810Dec 23, 2004
    risk 0.00cvss epss 0.02

    Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.

  • CVE-2001-0438Jul 2, 2001
    risk 0.00cvss epss 0.00

    Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.

  • CVE-2000-0086Jan 18, 2000
    risk 0.00cvss epss 0.01

    Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.