Vulnerabilities > Verisign

DATE CVE VULNERABILITY TITLE RISK
2008-10-07 CVE-2008-4393 Cross-Site Scripting vulnerability in Verisign Kontiki Delivery Management System
Cross-site scripting (XSS) vulnerability in VeriSign Kontiki Delivery Management System (DMS) 5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to zodiac/servlet/zodiac.
network
verisign CWE-79
4.3
2007-02-23 CVE-2007-1083 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Verisign Mpki
Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
network
verisign CWE-119
critical
9.3
2006-05-12 CVE-2006-2273 Remote Buffer Overflow vulnerability in Verisign i-Nav ActiveX Control
The InstallProduct routine in the Verisign VUpdater.Install (aka i-Nav) ActiveX control does not verify Microsoft Cabinet (.CAB) files, which allows remote attackers to run an arbitrary executable file.
network
verisign
critical
9.3
2006-03-22 CVE-2006-1344 Cross-Site Scripting vulnerability in Verisign Mpki 6.0
Cross-site scripting (XSS) vulnerability in VeriSign haydn.exe, as used in Managed PKI (MPKI) 6.0, allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the VHTML_FILE parameter.
network
verisign
4.3
2005-01-10 CVE-2004-1209 Remote Security vulnerability in Payflow Link
Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.
network
low complexity
verisign
5.0