VYPR
Vendor

Magic Software Enterprises

Products
5
CVEs
4
Across products
5
Status
Private

Products

5

Recent CVEs

4
  • CVE-2020-17446CriAug 12, 2020
    risk 0.57cvss 9.8epss 0.02

    asyncpg before 0.21.0 allows a malicious PostgreSQL server to trigger a crash or execute arbitrary code (on a database client) via a crafted server response, because of access to an uninitialized pointer in the array data decoder.

  • CVE-2023-52239MedFeb 6, 2024
    risk 0.42cvss 6.5epss 0.00

    The XML parser in Magic xpi Integration Platform 4.13.4 allows XXE attacks, e.g., via onItemImport.

  • CVE-2005-0315Jan 27, 2005
    risk 0.00cvss epss 0.01

    The FTP service in Magic Winmail Server 4.0 Build 1112 does not verify that the IP address in a PORT command is the same as the IP address of the user of the FTP session, which allows remote authenticated users to use the server as an intermediary for port scanning.

  • CVE-2001-1448Dec 17, 2001
    risk 0.00cvss epss 0.01

    Magic eDeveloper Enterprise Edition 8.30-5 and earlier allows local users to overwrite arbitrary files and possibly execute code via a symlink attack on temporary files created by the (1) mkuserproc, (2) mgrnt, and (3) mgdatasrvr.sc scripts.