Latest CVE Feed
-
8.8
HIGHCVE-2017-8332
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of blocking key words passing in the web traffic to prevent kids from watching content that might be deemed ... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-8331
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of adding new port forwarding rules to the device. It seems that the POST parameters passed in this request ... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-8330
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a UPnP functionality for devices to interface with the router and interact with the device. It seems that the "NewInMessage" SOAP param... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2017-8329
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of setting a name for the wireless network. These values are stored by the device in NVRAM (Non-volatile RAM... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-8328
An issue was discovered on Securifi Almond, Almond+, and Almond 2015 devices with firmware AL-R096. The device provides a user with the capability of changing the administrative password for the web management interface. It seems that the device does not ... Read more
Affected Products : almond_2015_firmware almond\+firmware almond_firmware almond almond_2015 almond\+- Published: Jun. 18, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-8316
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.... Read more
Affected Products : intellij_idea- Published: Aug. 03, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-8315
Eclipse XML parser for the Eclipse IDE versions 2017.2.5 and earlier was found vulnerable to an XML External Entity attack. An attacker can exploit the vulnerability by implementing malicious code on Androidmanifest.xml.... Read more
Affected Products : ide- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-8276
Improper authorization involving a fuse in TrustZone in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/... Read more
Affected Products : sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware sdx24_firmware mdm9206_firmware mdm9607_firmware +56 more products- Published: Jan. 18, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-8275
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, SD 400, SD 430, SD 450, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 820, SD 835, an integer overflow vulnerability exists in a video library.... Read more
Affected Products : android sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_430_firmware sd_650_firmware +19 more products- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-8274
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, an access control vulnerability exists in Core.... Read more
Affected Products : android sd_450_firmware sd_625_firmware msm8909w_firmware mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware +15 more products- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-8252
Kernel can inject faults in computations during the execution of TrustZone leading to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon... Read more
Affected Products : ipq8074_firmware qca8081_firmware sd_8cx_firmware sdm660_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware +100 more products- Published: Jun. 14, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-8230
On Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices, the users on the device are divided into 2 groups "admin" and "user". However, as a part of security analysis it was identified that a low privileged user who belongs to the "user" group and who has a... Read more
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8229
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices allow an unauthenticated attacker to download the administrative credentials. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using binwalk tool, one obtains a _user-x.squashfs.img.extracte... Read more
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-8228
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices mishandle reboots within the past two hours. Amcrest cloud services does not perform a thorough verification when allowing the user to add a new camera to the user's account to ensure that the user actual... Read more
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8227
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have a timeout policy to wait for 5 minutes in case 30 incorrect password attempts are detected using the Web and HTTP API interface provided by the device. However, if the same brute force attempt is per... Read more
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-8226
Amcrest IPM-721S V2.420.AC00.16.R.20160909 devices have default credentials that are hardcoded in the firmware and can be extracted by anyone who reverses the firmware to identify them. If the firmware version V2.420.AC00.16.R 9/9/2016 is dissected using ... Read more
- Published: Jul. 03, 2019
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2017-8187
Huawei FusionSphere OpenStack V100R006C00SPC102(NFV) has a privilege escalation vulnerability. Due to improper privilege restrictions, an attacker with high privilege may obtain the other users' certificates. Successful exploit may cause privilege escalat... Read more
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-8176
Huawei IPTV STB with earlier than IPTV STB V100R003C01LMYTa6SPC001 versions has an authentication bypass vulnerability. An attacker could exploit this vulnerability to access the serial interface and modify the configuration. Successful exploit could lead... Read more
- Published: Mar. 20, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2017-8165
Mate 9 Huawei smart phones with versions earlier than MHA-AL00BC00B233 have a sensitive information leak vulnerability. An attacker can trick a user to install a malicious application to exploit this vulnerability. Successful exploitation may cause sensit... Read more
- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2017-8164
Some Huawei smart phones with software EVA-L09C34B142; EVA-L09C40B196; EVA-L09C432B210; EVA-L09C440B138; EVA-L09C464B150; EVA-L09C530B127; EVA-L09C55B190; EVA-L09C576B150; EVA-L09C635B221; EVA-L09C636B193; EVA-L09C675B130; EVA-L09C688B143; EVA-L09C703B160... Read more
Affected Products : vie-l09_firmware eva-al10_firmware eva-cl00_firmware eva-dl00_firmware eva-l09_firmware eva-l19_firmware eva-l29_firmware eva-tl00_firmware vie-l29_firmware eva-l09 +8 more products- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024