CVE Tools

Janrain

6 CVEs tracked since 2011. Since Feb 2011, none of them reached CISA KEV.

Janrain CVEs per month

Feb 2011 to Feb 2016. Point at a month, or focus the strip and use the arrow keys.
Janrain CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2011-0210
2011-03null or fewer
2011-04null or fewer
2011-05null or fewer
2011-06null or fewer
2011-07null or fewer
2011-08null or fewer
2011-0910
2011-10null or fewer
2011-11null or fewer
2011-12null or fewer
2012-01null or fewer
2012-02null or fewer
2012-03null or fewer
2012-04null or fewer
2012-05null or fewer
2012-06null or fewer
2012-0710
2012-08null or fewer
2012-09null or fewer
2012-10null or fewer
2012-11null or fewer
2012-12null or fewer
2013-01null or fewer
2013-02null or fewer
2013-03null or fewer
2013-04null or fewer
2013-05null or fewer
2013-06null or fewer
2013-07null or fewer
2013-0810
2013-09null or fewer
2013-10null or fewer
2013-11null or fewer
2013-1210
2014-01null or fewer
2014-02null or fewer
2014-03null or fewer
2014-04null or fewer
2014-05null or fewer
2014-06null or fewer
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-05null or fewer
2015-06null or fewer
2015-07null or fewer
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-12null or fewer
2016-01null or fewer
2016-0210

Products

The products that kept showing up in Janrain's monthly top three, with their CVEs summed over those months.

  1. Php-openid33 months
  2. Rpx22 months
  3. Ruby-openid11 month

Latest CVEs

The 6 most recently published vulnerabilities affecting Janrain.

  1. CVE-2016-2049examples/consumer/common.php in JanRain PHP OpenID library (aka php-openid) improperly checks the openid.realm parameter against the SERVER_NAME element in the SERVER superglobal array, which might...8.8
  2. CVE-2013-1812The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.4.3
  3. CVE-2013-4701Auth/Yadis/XML.php in PHP OpenID Library 2.2.2 and earlier allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory cons...7.5
  4. CVE-2012-2296The Janrain Engage (formerly RPX) module for Drupal 6.x-1.x. 6.x-2.x before 6.x-2.2, and 7.x-2.x before 7.x-2.2 stores user profile data from Engage in session tables, which might allow remote atta...5.0
  5. CVE-2011-3707JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error messag...5.0
  6. CVE-2011-0771The Janrain Engage (formerly RPX) module 6.x-1.3 for Drupal does not validate the file for a profile image, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks and...6.8

The record

Peak rank
#73 in Feb 2011
Busiest month shown
Feb 2011, 1 CVEs
Months with a KEV entry
0 since Feb 2011
Monthly snapshots
6 since 2011
Janrain's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store