Abledesign maintains a small portfolio of consumer-oriented web and multimedia applications including dynamic picture frames and calendar utilities, with its vulnerability profile centered on web application input handling and cross-site scripting weaknesses. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Abledesign over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-1050MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in index.php in AbleDesign MyCalendar allow remote attackers to inject arbitrary web script or HTML via (1) the go parameter, (2 | Feb 21, 2007 | 4.3 | 22 | NO | YES |
CVE-2005-4435MEDIUM Cross-site scripting (XSS) vulnerability in index.php AbleDesign D-Man 3.x allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provena | Dec 21, 2005 | 4.3 | 21 | NO | YES |
CVE-2007-4624MEDIUM Cross-site scripting (XSS) vulnerability in pframe.php in AbleDesign Dynamic Picture Frame 1.00 allows remote attackers to inject arbitrary web script or HTML via the img_url param | Aug 31, 2007 | 4.3 | 14 | NO | NO |
CVE-2005-4434MEDIUM Cross-site scripting (XSS) vulnerability in AbleDesign ReSearch 2.x allows remote attackers to inject arbitrary web script or HTML via unknown vectors. NOTE: the provenance of this | Dec 21, 2005 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Abledesign.
Media articles that mention a CVE ID that affects a product developed by Abledesign — matched by CVE ID, not by vendor name.