Show filters
664 Total Results
Displaying 421-430 of 664
Sort by:
Attacker Value
Unknown

Incorrect privilege assignment in the app permission update API of the Bosch Sm…

Disclosure Date: May 29, 2019 (last updated November 27, 2024)
A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app with restricted permissions, which required user interaction.
Attacker Value
Unknown

Eaton Halo Home Android App Insecure Storage

Disclosure Date: May 22, 2019 (last updated November 27, 2024)
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored OAuth token, thus allowing them to view and change the user's personal information stored in the backend cloud service. The attacker would first need to gain physical control of the Android device or compromise it with a malicious app.
Attacker Value
Unknown

CVE-2019-9659

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
The Chuango 433 MHz burglar-alarm product line uses static codes in the RF remote control, allowing an attacker to arm, disarm, or trigger the alarm remotely via replay attacks, as demonstrated by Chuango branded products, and non-Chuango branded products such as the Eminent EM8617 OV2 Wifi Alarm System.
0
Attacker Value
Unknown

CVE-2018-3898

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the ssid_dst field.
Attacker Value
Unknown

CVE-2018-3891

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-3899

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the password_dst field
Attacker Value
Unknown

CVE-2018-3890

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-3935

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-3934

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability.
Attacker Value
Unknown

CVE-2018-3892

Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability.