Skip to content
Noroxi

OpenID records

7 published records for vendor openid.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
42.9%
Median publish → KEV
No record has entered KEV

All records

7 records
  • Ruby OpenID (aka ruby-openid) through 2.8.0 has a remotely exploitable flaw.

    CriticalCVSS 9.8No exploitEPSS 3%

    openid · ruby-openidJun 10, 2019

  • CVE-2007-1652
    30Monitor

    OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and

    HighCVSS 7.5No exploitEPSS 1%

    openid · openidMar 23, 2007

  • CVE-2007-5173
    28Monitor

    PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute

    MediumCVSS 6.8Proof of conceptEPSS 3%

    openid · openidOct 3, 2007

  • CVE-2007-1651
    27Monitor

    Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enable

    MediumCVSS 6.8No exploitEPSS 1%

    openid · openidMar 23, 2007

  • CVE-2008-3280
    24Monitor

    It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Debian Predictable Rand

    MediumCVSS 5.9Proof of conceptEPSS 4%

    openid · openidMay 21, 2021

  • CVE-2011-4314
    24Monitor

    message/ax/AxMessage.java in OpenID4Java before 0.9.6 final, as used in JBoss Enterprise Application Platform 5.1 before 5.1.2, Step2, Kay F

    MediumCVSS 5.8No exploitEPSS 3%

    openid · openid4javaJan 27, 2012

  • CVE-2019-9837
    24Monitor

    Doorkeeper::OpenidConnect (aka the OpenID Connect extension for Doorkeeper) 1.4.x and 1.5.x before 1.5.4 has an open redirect via the redire

    MediumCVSS 6.1No exploitEPSS 1%

    openid · openid connectMar 21, 2019