Show filters
274 Total Results
Displaying 121-130 of 274
Sort by:
Attacker Value
Unknown

CVE-2018-18005

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Cross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript via a URL query string parameter.
0
Attacker Value
Unknown

CVE-2018-18004

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Incorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote attackers to enable arbitrary system services via a URL parameter.
0
Attacker Value
Unknown

CVE-2018-18244

Disclosure Date: January 03, 2019 (last updated November 27, 2024)
Cross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to execute arbitrary JavaScript code via an HTTP Referer Header.
0
Attacker Value
Unknown

CVE-2018-18602

Disclosure Date: December 31, 2018 (last updated November 27, 2024)
The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring.
0
Attacker Value
Unknown

CVE-2018-18767

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.
0
Attacker Value
Unknown

CVE-2018-20299

Disclosure Date: December 19, 2018 (last updated November 27, 2024)
An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser of the web server.
Attacker Value
Unknown

CVE-2018-20051

Disclosure Date: December 10, 2018 (last updated November 27, 2024)
Mishandling of '>' on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via certain ONVIF methods such as CreateUsers, SetImagingSettings, GetStreamUri, and so on.
0
Attacker Value
Unknown

CVE-2018-20050

Disclosure Date: December 10, 2018 (last updated November 27, 2024)
Mishandling of an empty string on the Jooan JA-Q1H Wi-Fi camera with firmware 21.0.0.91 allows remote attackers to cause a denial of service (crash and reboot) via the ONVIF GetStreamUri method and GetVideoEncoderConfigurationOptions method.
0
Attacker Value
Unknown

CVE-2018-3898

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the ssid_dst field.
Attacker Value
Unknown

CVE-2018-3891

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability.