Skip to main content

Vendor/product archive

inedo / otter CVEs

Beta · best-effort

2 CVEs tagged to inedo / otter2 Critical, 0 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2017-17086

Published Dec 1, 2017

Indeo Otter through 1.7.4 mishandles a "</script>" substring in an initial DP payload, which allows remote attackers to cause a denial of service (crash) or possibly have unspecif…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2017-15607

Published Dec 1, 2017

Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1