Show filters
17 Total Results
Displaying 11-17 of 17
Sort by:
Attacker Value
Unknown
CVE-2018-7580
Disclosure Date: December 21, 2020 (last updated February 22, 2025)
Philips Hue is vulnerable to a Denial of Service attack. Sending a SYN flood on port tcp/80 will freeze Philips Hue's hub and it will stop responding. The "hub" will stop operating and be frozen until the flood stops. During the flood, the user won't be able to turn on/off the lights, and all of the hub's functionality will be unresponsive. The cloud service also won't work with the hub.
0
Attacker Value
Unknown
CVE-2020-6007
Disclosure Date: January 23, 2020 (last updated February 21, 2025)
Philips Hue Bridge model 2.X prior to and including version 1935144020 contains a Heap-based Buffer Overflow when handling a long ZCL string during the commissioning phase, resulting in a remote code execution.
0
Attacker Value
Unknown
CVE-2018-11649
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
0
Attacker Value
Unknown
CVE-2015-8094
Disclosure Date: May 22, 2018 (last updated November 26, 2024)
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
0
Attacker Value
Unknown
CVE-2017-14797
Disclosure Date: October 01, 2017 (last updated November 26, 2024)
Lack of Transport Encryption in the public API in Philips Hue Bridge BSB002 SW 1707040932 allows remote attackers to read API keys (and consequently bypass the pushlink protection mechanism, and obtain complete control of the connected accessories) by leveraging the ability to sniff HTTP traffic on the local intranet network.
0
Attacker Value
Unknown
CVE-2016-4946
Disclosure Date: March 07, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Cloudera HUE 3.9.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) First name or (2) Last name field in the HUE Users page.
0
Attacker Value
Unknown
CVE-2016-4947
Disclosure Date: March 07, 2017 (last updated November 26, 2024)
Cloudera HUE 3.9.0 and earlier allows remote attackers to enumerate user accounts via a request to desktop/api/users/autocomplete.
0