Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-38536

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.  
0
Attacker Value
Unknown

CVE-2023-38535

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.  
0
Attacker Value
Unknown

CVE-2023-38534

Disclosure Date: March 13, 2024 (last updated April 01, 2024)
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC. 
0
Attacker Value
Unknown

CVE-2013-6806

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.
0
Attacker Value
Unknown

CVE-2013-6805

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
0
Attacker Value
Unknown

CVE-2013-6994

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
0
Attacker Value
Unknown

CVE-2013-6807

Disclosure Date: May 19, 2014 (last updated October 05, 2023)
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown

CVE-2008-4729

Disclosure Date: October 24, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.
0
Attacker Value
Unknown

CVE-2004-2258

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
0
Attacker Value
Unknown

CVE-1999-1196

Disclosure Date: April 07, 1999 (last updated February 22, 2025)
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
0