Vulnerabilities > Hummingbird

DATE CVE VULNERABILITY TITLE RISK
2008-10-24 CVE-2008-4729 Buffer Errors vulnerability in Hummingbird Exceed and Exceed Powersuite
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Control 13.0 and earlier allows remote attackers to execute arbitrary code via a long PlainTextPassword property.
6.8
2006-01-11 CVE-2006-0174 Multiple vulnerability in Hummingbird Collaboration and Enterprise Collaboration
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.
network
low complexity
hummingbird
4.0
2006-01-11 CVE-2006-0173 Multiple vulnerability in Hummingbird Enterprise Collaboration 5.2/5.21
Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.
network
low complexity
hummingbird
4.0
2006-01-11 CVE-2006-0172 Multiple vulnerability in Hummingbird Enterprise Collaboration 5.2/5.21
Cross-site scripting (XSS) vulnerability in the file manager utility in Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to inject arbitrary web script or HTML in an uploaded page, which is published without a check for hostile scripting.
network
hummingbird
3.5
2005-08-17 CVE-2005-2599 Unspecified vulnerability in Hummingbird Connectivity 10.0
Hummingbird FTP for Connectivity 10.0 uses weak encryption (trivial encoding) to store the user's password in the FTP profile, which allows attackers to gain privileges.
network
low complexity
hummingbird
7.5
2005-06-01 CVE-2005-1815 Stack Overflow vulnerability in Hummingbird Connectivity 10.0/7.1/9.0
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of service and possibly execute arbitrary code via (1) an FTP command with a long argument to FTPD (ftpdw.exe) or (2) a large amount of data to LPD (Lpdw.exe).
network
low complexity
hummingbird
5.0
2004-12-31 CVE-2004-2729 Permissions, Privileges, and Access Controls vulnerability in Hummingbird Connectivity 7.1/9.0
Inetd32 Administration Tool of Hummingbird Connectivity 7.1 and 9.0 allows local users to execute arbitrary code by changing the program for handling incoming connections.
4.4
2004-12-31 CVE-2004-2728 Buffer Errors vulnerability in Hummingbird Connectivity 7.1/9.0
Buffer overflow in the FTP server of Hummingbird Connectivity 7.1 and 9.0 allows remote, authenticated users to cause a denial of service (application crash) via a long argument to the XCWD command.
3.5
2004-12-31 CVE-2004-2258 Unspecified vulnerability in Hummingbird Exceed 9.0
Xconfig in Hummingbird Exceed before 9.0.0.1, when the Screen Definition is password-protected, allows local users to access certain options by switching to another tab, then switching back to the original tab.
local
low complexity
hummingbird
2.1
2003-12-31 CVE-2003-1103 SQL Injection vulnerability in Hummingbird Cyberdocs 3.1/3.5.1
SQL injection vulnerability in loginact.asp for Hummingbird CyberDOCS before 3.9 allows remote attackers to execute arbitrary SQL commands.
network
low complexity
hummingbird
7.5