Lucene search

K

Owl Security Vulnerabilities

cve
cve

CVE-2024-5345

The Responsive Owl Carousel for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.2.0 via the layout parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary...

8.8CVSS

7.6AI Score

0.001EPSS

2024-05-31 03:15 AM
27
cve
cve

CVE-2023-51493

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Howard Ehrenberg Custom Post Carousels with Owl allows Stored XSS.This issue affects Custom Post Carousels with Owl: from n/a through...

6.5CVSS

5.4AI Score

0.0004EPSS

2024-02-10 09:15 AM
33
cve
cve

CVE-2024-24801

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LogicHunt OWL Carousel – WordPress Owl Carousel Slider allows Stored XSS.This issue affects OWL Carousel – WordPress Owl Carousel Slider: from n/a through...

6.5CVSS

6.3AI Score

0.0004EPSS

2024-02-10 08:15 AM
54
cve
cve

CVE-2023-23829

Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pierre JEHAN Owl Carousel plugin <= 0.5.3...

6.5CVSS

4.8AI Score

0.0004EPSS

2023-08-08 12:15 PM
76
cve
cve

CVE-2022-29277

Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R:...

8.8CVSS

8.6AI Score

0.0004EPSS

2022-11-15 10:15 PM
31
4
cve
cve

CVE-2009-5082

The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary...

6.1AI Score

0.0004EPSS

2022-10-03 04:24 PM
25
cve
cve

CVE-2022-31463

Owl Labs Meeting Owl 5.2.0.15 does not require a password for Bluetooth commands, because only client-side authentication is...

8.2CVSS

7.6AI Score

0.001EPSS

2022-06-02 10:15 PM
87
In Wild
7
cve
cve

CVE-2022-31461

Owl Labs Meeting Owl 5.2.0.15 allows attackers to deactivate the passcode protection mechanism via a certain c 11...

7.4CVSS

6.9AI Score

0.001EPSS

2022-06-02 10:15 PM
95
In Wild
4
cve
cve

CVE-2022-31462

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast...

9.3CVSS

8.6AI Score

0.001EPSS

2022-06-02 10:15 PM
61
In Wild
7
cve
cve

CVE-2022-31459

Owl Labs Meeting Owl 5.2.0.15 allows attackers to retrieve the passcode hash via a certain c 10 value over...

7.4CVSS

6.9AI Score

0.001EPSS

2022-06-02 10:15 PM
75
In Wild
4
cve
cve

CVE-2022-31460

Owl Labs Meeting Owl 5.2.0.15 allows attackers to activate Tethering Mode with hard-coded hoothoot credentials via a certain c 150...

7.4CVSS

7.4AI Score

0.001EPSS

2022-06-02 10:15 PM
709
In Wild
6
cve
cve

CVE-2009-0363

Multiple buffer overflows in (a) BarnOwl before 1.0.5 and (b) owl 2.1.11 allow remote attackers to execute arbitrary code via vectors involving (1) a crafted zcrypt message, related to zcrypt.c; (2) a reply command on a message with a Zephyr Cc: list, related to zwrite.c; and unspecified other use....

8.1AI Score

0.106EPSS

2009-02-17 05:30 PM
31
cve
cve

CVE-2006-4212

SQL injection vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified...

8.4AI Score

0.01EPSS

2006-08-17 09:04 PM
36
cve
cve

CVE-2006-4211

Cross-site scripting (XSS) vulnerability in b0zz and Chris Vincent Owl Intranet Engine 0.90 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified...

5.7AI Score

0.006EPSS

2006-08-17 09:04 PM
25
cve
cve

CVE-2006-1149

PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before...

6.8AI Score

0.1EPSS

2006-03-10 11:02 AM
30
cve
cve

CVE-2005-0264

Multiple cross-site scripting (XSS) vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) expand or (2) order...

5.8AI Score

0.004EPSS

2005-05-02 04:00 AM
26
cve
cve

CVE-2005-0265

Multiple SQL injection vulnerabilities in browse.php in OWL 0.7 and 0.8 allow remote attackers to execute arbitrary SQL commands via the (1) parent or (2) sortposted...

8.5AI Score

0.002EPSS

2005-05-02 04:00 AM
25
cve
cve

CVE-2003-0341

Cross-site scripting (XSS) vulnerability in Owl Intranet Engine 0.71 and earlier allows remote attackers to insert arbitrary script via the Search...

6.2AI Score

0.004EPSS

2003-05-23 04:00 AM
25