MidnightBSD

Advisories for oxid

CVE-2005-0807 HIGH

Multiple buffer overflows in Cain & Abel before 2.67 allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via (1) an IKE packet with a large ID field that is not properly handled by the PSK sniffer filter, (2) the HTTP sniffer filter, or the (3) POP3, (4) SMTP, (5) IMAP, (6) NNTP, or (7) TDS sniffer filters.

CVSS 2.0

Severity: HIGH

Problem Type: NVD-CWE-Other,

Products Affected

Vendor Product Version
oxid cain_and_abel 2.5_beta47
oxid cain_and_abel 2.65
oxid cain_and_abel 2.5_beta29
oxid cain_and_abel 2.5_beta65
oxid cain_and_abel 2.5_beta36
oxid cain_and_abel 2.5_beta40
oxid cain_and_abel 2.5_beta56
oxid cain_and_abel 2.5_beta59
oxid cain_and_abel 2.5_beta51
oxid cain_and_abel 2.5
oxid cain_and_abel 2.5_beta21
oxid cain_and_abel 2.5_beta41
oxid cain_and_abel 2.5_beta34
CVE-2008-5405 HIGH

Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier, allows remote attackers to execute arbitrary code via an RDP file containing a long string.

CVSS 2.0

Severity: HIGH

Problem Type: CWE-119,

Products Affected

Vendor Product Version
oxid cain_and_abel 4.9.24
oxid cain_and_abel 4.9.23
CVE-2009-2266 MEDIUM

OXID eShop 4.x before 4.1.4-21266, 3.x, and 2.x allows remote attackers to obtain sensitive information (session details and order history of other users) via a crafted cookie.

CVSS 2.0

Severity: MEDIUM

Problem Type: CWE-200,

Products Affected

Vendor Product Version
oxid eshop 4.0.0.0_14260
oxid eshop 4.0.0.0_13934
oxid eshop 4.1.2-18998
oxid eshop 4.1.3-19918
oxid eshop 4.0.0.0_13895
oxid eshop 4.1.0-17976
oxid eshop 4.0.0.2_14967
oxid eshop 4.0.0.2_14842
oxid eshop *
oxid eshop 4.0.0.1_14455
oxid eshop 4.1.1-18442
oxid eshop 4.0.1.0_15990
CVE-2009-3113 MEDIUM

Unspecified vulnerability in OXID eShop Professional, Enterprise, and Community Edition before 4.1.2, 3.x, and 2.x allows remote attackers to gain write access to product reviews via a crafted parameter.

CVSS 2.0

Severity: MEDIUM

Problem Type: NVD-CWE-noinfo,

Products Affected

Vendor Product Version
oxid eshop 4.0.0.0_14260
oxid eshop 4.0.0.0_13934
oxid eshop 4.1.2-18998
oxid eshop 4.1.3-19918
oxid eshop 4.0.0.0_13895
oxid eshop 4.1.0-17976
oxid eshop 4.0.0.2_14967
oxid eshop 4.0.0.2_14842
oxid eshop *
oxid eshop 4.0.0.1_14455
oxid eshop 4.1.1-18442
oxid eshop 4.0.1.0_15990