Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown
CVE-2023-38536
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
HTML injection in OpenText™ Exceed Turbo X affecting version 12.5.1. The vulnerability could result in Cross site scripting.
0
Attacker Value
Unknown
CVE-2023-38535
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
Use of Hard-coded Cryptographic Key vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.1 and 12.5.2. The vulnerability could compromise the cryptographic keys.
0
Attacker Value
Unknown
CVE-2023-38534
Disclosure Date: March 13, 2024 (last updated April 01, 2024)
Improper authentication vulnerability in OpenText™ Exceed Turbo X affecting versions 12.5.0 and 12.5.1. The vulnerability could allow disclosure of restricted information in unauthenticated RPC.
0
Attacker Value
Unknown
CVE-2013-6806
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 allows man-in-the-middle attackers to disable bidirectional authentication and obtain sensitive information via a crafted string in a response, which triggers a downgrade to simple authentication that sends credentials in plaintext.
0
Attacker Value
Unknown
CVE-2013-6805
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 uses weak encryption for passwords, which makes it easier for (1) remote attackers to discover credentials by sniffing the network or (2) local users to discover credentials by reading a .eod8 file.
0
Attacker Value
Unknown
CVE-2013-6994
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
OpenText Exceed OnDemand (EoD) 8 transmits the session ID in cleartext, which allows remote attackers to perform session fixation attacks by sniffing the network.
0
Attacker Value
Unknown
CVE-2013-6807
Disclosure Date: May 19, 2014 (last updated October 05, 2023)
The client in OpenText Exceed OnDemand (EoD) 8 supports anonymous ciphers by default, which allows man-in-the-middle attackers to bypass server certificate validation, redirect a connection, and obtain sensitive information via crafted responses.
0
Attacker Value
Unknown
CVE-2008-4729
Disclosure Date: October 24, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.
0
Attacker Value
Unknown
CVE-2004-2258
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
0
Attacker Value
Unknown
CVE-1999-1196
Disclosure Date: April 07, 1999 (last updated February 22, 2025)
Hummingbird Exceed X version 5 allows remote attackers to cause a denial of service via malformed data to port 6000.
0