Show filters
162 Total Results
Displaying 11-20 of 162
Sort by:
Attacker Value
Unknown

CVE-2024-5463

Disclosure Date: June 04, 2024 (last updated June 04, 2024)
A vulnerability regarding buffer copy without checking the size of input ('Classic Buffer Overflow') has been found in the login component. This allows remote attackers to conduct denial-of-service attacks via unspecified vectors. This attack only affects the login service which will automatically restart. The following models with Synology Camera Firmware versions before 1.1.1-0383 may be affected: BC500 and TC500.
0
Attacker Value
Unknown

CVE-2023-6324

Disclosure Date: May 15, 2024 (last updated February 12, 2025)
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
Attacker Value
Unknown

CVE-2023-6323

Disclosure Date: May 15, 2024 (last updated February 12, 2025)
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
Attacker Value
Unknown

CVE-2023-6322

Disclosure Date: May 15, 2024 (last updated February 12, 2025)
A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-51820

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-50488

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-35867

Disclosure Date: December 18, 2023 (last updated December 23, 2023)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
Attacker Value
Unknown

CVE-2021-45039

Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer overflow, a remote attacker can start the telnetd service. This service has a hardcoded default username and password (root/123456). Although it has a restrictive shell, this can be easily bypassed via the built-in ECHO shell command.
Attacker Value
Unknown

CVE-2023-29861

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
Attacker Value
Unknown

CVE-2023-29862

Disclosure Date: May 15, 2023 (last updated October 08, 2023)
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.