VYPR
Vendor

Eeye

Products
5
CVEs
7
Across products
9
Status
Private

Products

5

Recent CVEs

7
  • CVE-2009-3859Nov 4, 2009
    risk 0.04cvss epss 0.12

    Buffer overflow in eEye Retina WiFi Scanner 1.0.8.68, as used in Retina Network Security Scanner 5.10.14, allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a .rws file with a long RWS010 entry.

  • CVE-2013-6657Feb 24, 2014
    risk 0.00cvss epss 0.01

    core/html/parser/XSSAuditor.cpp in the XSS auditor in Blink, as used in Google Chrome before 33.0.1750.117, inserts the about:blank URL during certain blocking of FORM elements within HTTP requests, which allows remote attackers to bypass the Same Origin Policy and obtain…

  • CVE-2013-6649Jan 28, 2014
    risk 0.00cvss epss 0.01

    Use-after-free vulnerability in the RenderSVGImage::paint function in core/rendering/svg/RenderSVGImage.cpp in Blink, as used in Google Chrome before 32.0.1700.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors…

  • CVE-2010-5155Aug 25, 2012
    risk 0.00cvss epss 0.00

    Race condition in Blink Professional 4.6.1 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes…

  • CVE-2011-3337Jan 4, 2012
    risk 0.00cvss epss 0.00

    eEye Audit ID 2499 in eEye Digital Security Audits 2406 through 2423 for eEye Retina Network Security Scanner on HP-UX, IRIX, and Solaris allows local users to gain privileges via a Trojan horse gauntlet program in an arbitrary directory under /usr/local/.

  • CVE-2001-0523Aug 14, 2001
    risk 0.00cvss epss 0.02

    eEye SecureIIS versions 1.0.3 and earlier allows a remote attacker to bypass filtering of requests made to SecureIIS by escaping HTML characters within the request, which could allow a remote attacker to use restricted variables and perform directory traversal attacks on…

  • CVE-2001-0524Aug 14, 2001
    risk 0.00cvss epss 0.02

    eEye SecureIIS versions 1.0.3 and earlier does not perform length checking on individual HTTP headers, which allows a remote attacker to send arbitrary length strings to IIS, contrary to an advertised feature of SecureIIS versions 1.0.3 and earlier.