Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown
CVE-2008-4728
Disclosure Date: October 24, 2008 (last updated October 04, 2023)
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in Hummingbird Deployment Wizard 2008 allow remote attackers to execute arbitrary programs via the (1) Run and (2) PerformUpdateAsync methods, and (3) modify arbitrary registry values via the SetRegistryValueAsString method. NOTE: the SetRegistryValueAsString method could be leveraged for code execution by specifying executable file values to Startup folders.
0
Attacker Value
Unknown
CVE-2008-4729
Disclosure Date: October 24, 2008 (last updated October 04, 2023)
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property. NOTE: code execution might not be possible in 13.0.
0
Attacker Value
Unknown
CVE-2006-0172
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.
0
Attacker Value
Unknown
CVE-2006-0173
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.
0
Attacker Value
Unknown
CVE-2006-0174
Disclosure Date: January 11, 2006 (last updated February 22, 2025)
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
0
Attacker Value
Unknown
CVE-2005-2599
Disclosure Date: August 17, 2005 (last updated February 22, 2025)
Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.
0
Attacker Value
Unknown
CVE-2005-1815
Disclosure Date: June 01, 2005 (last updated February 22, 2025)
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe).
0
Attacker Value
Unknown
CVE-2004-2258
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
0
Attacker Value
Unknown
CVE-2004-2728
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.
0
Attacker Value
Unknown
CVE-2004-2729
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.
0