Omnigroup maintains a focused portfolio centered on specialized productivity and information-management applications, most notably OmniWeb, a web browser positioned in a narrow market segment. The vendor's vulnerability disclosures recur through weakness classes including NULL pointer dereferences and parsing-related flaws typical of application software handling complex data structures. Exploit tooling has been developed for some of this vendor's vulnerabilities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Omnigroup over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-0233HIGH The International Domain Name (IDN) support in Firefox 1.0, Camino .8.5, and Mozilla before 1.7.6 allows remote attackers to spoof domain names using punycode encoded domain names | Feb 8, 2005 | 7.5 | 31 | NO | NO |
CVE-2007-0148MEDIUM Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifie | Jan 9, 2007 | 6.8 | 29 | NO | YES |
CVE-2007-0342HIGH WebCore in Apple WebKit build 18794 allows remote attackers to cause a denial of service (null dereference and application crash) via a TD element with a large number in the ROWSPA | Jan 18, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-0238MEDIUM The International Domain Name (IDN) support in Epiphany allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certifica | May 2, 2005 | 5.0 | 17 | NO | NO |
CVE-2010-1102MEDIUM Integer overflow in OmniWeb allows remote attackers to bypass intended port restrictions on outbound TCP connections via a port number outside the range of the unsigned short data | Mar 24, 2010 | 5.0 | 15 | NO | NO |
CVE-2005-0236MEDIUM The International Domain Name (IDN) support in Omniweb 5 allows remote attackers to spoof domain names using punycode encoded domain names that are decoded in URLs and SSL certific | May 2, 2005 | 5.0 | 15 | NO | NO |
CVE-2005-0976MEDIUM AppleWebKit (WebCore and WebKit), as used in multiple products such as Safari 1.2 and OmniGroup OmniWeb 5.1, allows remote attackers to read arbitrary files via the XMLHttpRequest | May 2, 2005 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Omnigroup.
Media articles that mention a CVE ID that affects a product developed by Omnigroup — matched by CVE ID, not by vendor name.