Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown

CVE-2018-14733

Disclosure Date: July 05, 2019 (last updated November 27, 2024)
The Odoo Community Association (OCA) dbfilter_from_header module makes Odoo 8.x, 9.x, 10.x, and 11.x vulnerable to ReDoS (regular expression denial of service) under certain circumstances.
0
Attacker Value
Unknown

CVE-2018-14864

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
Incorrect access control in asset bundles in Odoo Community 9.0 through 11.0 and earlier and Odoo Enterprise 9.0 through 11.0 and earlier allows remote authenticated users to inject arbitrary web script via a crafted attachment.
0
Attacker Value
Unknown

CVE-2017-5871

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
Odoo Version <= 8.0-20160726 and Version 9 is affected by: CWE-601: Open redirection. The impact is: obtain sensitive information (remote).
0
Attacker Value
Unknown

CVE-2017-10804

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, remote attackers can bypass authentication under certain circumstances because parameters containing 0x00 characters are truncated before reaching the database layer. This occurs because Psycopg 2.x before 2.6.3 is used.
0
Attacker Value
Unknown

CVE-2017-10805

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.
0
Attacker Value
Unknown

CVE-2017-10803

Disclosure Date: July 04, 2017 (last updated November 26, 2024)
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, insecure handling of anonymization data in the Database Anonymization module allows remote authenticated privileged users to execute arbitrary Python code, because unpickle is used.
0
Attacker Value
Unknown

CVE-2017-9416

Disclosure Date: June 04, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in tools.file_open in Odoo 8.0, 9.0, and 10.0 allows remote authenticated users to read arbitrary local files readable by the Odoo service.
0