Show filters
662 Total Results
Displaying 221-230 of 662
Sort by:
Attacker Value
Unknown

CVE-2022-40507

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
Memory corruption due to double free in Core while mapping HLOS address to the list.
Attacker Value
Unknown

CVE-2022-22076

Disclosure Date: June 06, 2023 (last updated February 25, 2025)
information disclosure due to cryptographic issue in Core during RPMB read request.
Attacker Value
Unknown

CVE-2023-31763

Disclosure Date: May 24, 2023 (last updated February 25, 2025)
Weak security in the transmitter of AGShome Smart Alarm v1.0 allows attackers to gain full access to the system via a code replay attack.
Attacker Value
Unknown

CVE-2023-33338

Disclosure Date: May 23, 2023 (last updated February 25, 2025)
Old Age Home Management 1.0 is vulnerable to SQL Injection via the username parameter.
Attacker Value
Unknown

CVE-2022-36328

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to create arbitrary shares on arbitrary directories and exfiltrate sensitive files, passwords, users and device configurations was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This can only be exploited once an attacker gains root privileges on the devices using an authentication bypass issue or another vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.
Attacker Value
Unknown

CVE-2022-36327

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could allow an attacker to write files to locations with certain critical filesystem types leading to remote code execution was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires an authentication bypass issue to be triggered before this can be exploited.  This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.
Attacker Value
Unknown

CVE-2022-36326

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
An uncontrolled resource consumption vulnerability issue that could arise by sending crafted requests to a service to consume a large amount of memory, eventually resulting in the service being stopped and restarted was discovered in Western Digital My Cloud Home, My Cloud Home Duo, SanDisk ibi and Western Digital My Cloud OS 5 devices. This issue requires the attacker to already have root privileges in order to exploit this vulnerability.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191; My Cloud OS 5: before 5.26.202.
Attacker Value
Unknown

CVE-2022-4418

Disclosure Date: May 18, 2023 (last updated February 25, 2025)
Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40208.
Attacker Value
Unknown

CVE-2023-2739

Disclosure Date: May 16, 2023 (last updated February 24, 2025)
A vulnerability classified as problematic was found in Gira HomeServer up to 4.12.0.220829 beta. This vulnerability affects unknown code of the file /hslist. The manipulation of the argument lst with the input debug%27"><img%20src=x%20onerror=alert(document.cookie)> leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-229150 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2022-36329

Disclosure Date: May 10, 2023 (last updated February 24, 2025)
An improper privilege management issue that could allow an attacker to cause a denial of service over the OTA mechanism was discovered in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices.This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.