Skip to main content

Vendor/product archive

qbik / wingate CVEs

Beta · best-effort

13 CVEs tagged to qbik / wingate0 Critical, 3 High, 10 Medium, 0 Low, 0 Unrated.

CVE-2020-13866

Published Jun 8, 2020

WinGate v9.4.1.5998 has insecure permissions for the installation directory, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0802

Published Mar 4, 2009

Qbik WinGate, when transparent interception mode is enabled, uses the HTTP Host header to determine the remote endpoint, which allows remote attackers to bypass access controls fo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3606

Published Aug 12, 2008

Heap-based buffer overflow in the IMAP service in Qbik WinGate 6.2.2.1137 and earlier allows remote authenticated users to cause a denial of service (resource exhaustion) or possi…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2007-4335

Published Aug 14, 2007

Format string vulnerability in the SMTP server component in Qbik WinGate 5.x and 6.x before 6.2.2 allows remote attackers to cause a denial of service (service crash) via format s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4518

Published Nov 28, 2006

Qbik WinGate 6.1.4 and earlier allows remote attackers to cause a denial of service (CPU consumption) via a DNS request with a self-referencing compressed name pointer, which trig…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2917

Published Jul 10, 2006

Directory traversal vulnerability in the IMAP server in WinGate 6.1.2.1094 and 6.1.3.1096, and possibly other versions before 6.1.4 Build 1099, allows remote authenticated users t…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-2926

Published Jun 9, 2006

Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2004-0789

Published Dec 31, 2004

Multiple implementations of the DNS protocol, including (1) Poslib 1.0.2-1 and earlier as used by Posadis, (2) Axis Network products before firmware 3.13, and (3) Men & Mice Suite…

CVSS 5.0 · Medium

CVE-2004-0577

Published Dec 6, 2004

WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files from the root directory via a URL request to th…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2004-0578

Published Dec 6, 2004

WinGate 5.2.3 build 901 and 6.0 beta 2 build 942, and other versions such as 5.0.5, allows remote attackers to read arbitrary files via leading slash (//) characters in a URL requ…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1048

Published Dec 11, 2000

Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GE…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0441

Published Feb 22, 1999

Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector Service.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-1999-0291

Published Feb 1, 1999

The WinGate proxy is installed without a password, which allows remote attackers to redirect connections without authentication.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1