Oi operates email marketing and customer-facing service portals that serve a regional telecommunications and services customer base. The vendor's disclosed vulnerabilities reflect application-layer concerns across these systems. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Oi over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0919HIGH SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Us | Feb 28, 2006 | 7.5 | 19 | NO | NO |
CVE-2014-5916MEDIUM The Minha Oi (aka br.com.mobicare.minhaoi) application 1.15.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof ser | Sep 17, 2014 | 5.4 | 17 | NO | NO |
Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, o | Feb 28, 2006 | 1.7 | 16 | NO | YES |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Oi.
Media articles that mention a CVE ID that affects a product developed by Oi — matched by CVE ID, not by vendor name.