← Back

Netopia

netopia

11 CVEs • 6 products

Products (6)

Click to collapse
Toggle

CVEs (11)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netopia
1Timbuktu Pro
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consum...Show more
The instant message service in Timbuktu Pro 8.6.5 RC 229 and earlier for Windows allows remote attackers to cause (1) a denial of service (daemon crash) via an invalid Version field or (2) a denial of service (CPU consumption and daemon termination) via an invalid or partial message.Show less
1Netopia
1Timbuktu Pro
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
7.5 HIGH· v2
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted...Show more
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields.Show less
1Netopia
1Timbuktu Pro
Apr 23, 2026
Mar 14, 2008
N/A· v4
N/A· v3
10.0 HIGH· v2
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbi...Show more
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, allows remote attackers to upload files to arbitrary locations via a destination filename with a \ (backslash) character followed by ../ (dot dot slash) sequences. NOTE: this can be leveraged for code execution by writing to a Startup folder. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2007-4220.Show less
1Netopia
1Timbuktu Pro Mac
Apr 16, 2026
Dec 23, 2004
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Netopia Timbuktu 7.0.3 allows remote attackers to cause a denial of service (server process crash) via a certain data string that is sent to multiple simultaneous client connections to TCP port 407.
1Netopia
1Timbuktu Pro
Apr 16, 2026
Mar 25, 2002
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of connections to one of the ports (1417 - 1420).
1Netopia
1Timbuktu Mac
Apr 16, 2026
Jul 2, 2001
N/A· v4
N/A· v3
2.1 LOW· v2
Preview version of Timbuktu for Mac OS X allows local users to modify System Preferences without logging in via the About Timbuktu menu.
1Netopia
1R9100 Router
Apr 16, 2026
Mar 26, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netopia R9100 router version 4.6 allows authenticated users to cause a denial of service by using the router's telnet program to connect to the router's IP address, which causes a crash.
1Netopia
1650 St Isdn Router
Apr 16, 2026
Jan 9, 2001
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netopia ISDN Router 650-ST before 4.3.5 allows remote attackers to read system logs without authentication by directly connecting to the login screen and typing certain control characters.
1Netopia
1R Series Routers
Apr 16, 2026
May 16, 2000
N/A· v4
N/A· v3
3.6 LOW· v2
The Netopia R9100 router does not prevent authenticated users from modifying SNMP tables, even if the administrator has configured it to do so.
1Netopia
1Timbuktu Pro
Apr 16, 2026
Feb 11, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections to port 407 and 1417.
1Netopia
1Timbuktu Pro
Apr 16, 2026
Jan 18, 2000
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Netopia Timbuktu Pro sends user IDs and passwords in cleartext, which allows remote attackers to obtain them via sniffing.