Aggregates CVE and security vulnerability intelligence across all dream-multimedia-tv-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.
Historical issues mainly involve vendor risk path handling and vendor risk cross-site scripting and related problems; some flaws may lead to vendor impact file overwrite and vendor impact session compromise.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2015-4714 | Cross-site scripting (XSS) vulnerability in the DreamBox DM500-S allows remote attackers to inject arbitrary web script or HTML via the mode parameter to /body. | [email protected] | 4.3 | 1.03% | 2015-06-22 | 2026-06-16 |
| CVE-2012-1025 | Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in the file parameter. | [email protected] | 5.0 | 6.21% | 2012-02-07 | 2026-06-16 |
| CVE-2012-1024 | Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter. | [email protected] | 5.0 | 3.64% | 2012-02-07 | 2026-06-16 |
| CVE-2011-4716 | Directory traversal vulnerability in file in DreamBox DM800 1.6rc3, 1.5rc1, and earlier allows remote attackers to read arbitrary files via the file parameter. | [email protected] | 5.0 | 3.53% | 2011-12-08 | 2026-06-16 |