Show filters
664 Total Results
Displaying 431-440 of 664
Sort by:
Attacker Value
Unknown
CVE-2018-3920
Disclosure Date: November 02, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-3900
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. An attacker can make the camera scan a QR code to trigger this vulnerability. Alternatively, a user could be convinced to display a QR code from the internet to their camera, which could exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2018-3928
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a settings change, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-3910
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
An exploitable code execution vulnerability exists in the cloud OTA setup functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted SSID can cause a command injection, resulting in code execution. An attacker can cause a camera to connect to this SSID to trigger this vulnerability. Alternatively, an attacker can convince a user to connect their camera to this SSID.
0
Attacker Value
Unknown
CVE-2018-3947
Disclosure Date: November 01, 2018 (last updated November 27, 2024)
An exploitable information disclosure vulnerability exists in the phone-to-camera communications of Yi Home Camera 27US 1.8.7.0D. An attacker can sniff network traffic to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2018-16225
Disclosure Date: September 18, 2018 (last updated November 27, 2024)
The QBee MultiSensor Camera through 4.16.4 accepts unencrypted network traffic from clients (such as the QBee Cam application through 1.0.5 for Android and the Swisscom Home application up to 10.7.2 for Android), which results in an attacker being able to reuse cookies to bypass authentication and disable the camera.
0
Attacker Value
Unknown
CVE-2017-17691
Disclosure Date: September 07, 2018 (last updated November 27, 2024)
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitive information via a man in the middle attack.
0
Attacker Value
Unknown
CVE-2018-13512
Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for SmartHomeCoin, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown
CVE-2018-7779
Disclosure Date: July 03, 2018 (last updated November 27, 2024)
In Schneider Electric Wiser for KNX V2.1.0 and prior, homeLYnk V2.0.1 and prior; and spaceLYnk V2.1.0 and prior, weak and unprotected FTP access could allow an attacker unauthorized access.
0
Attacker Value
Unknown
CVE-2018-0600
Disclosure Date: June 26, 2018 (last updated November 26, 2024)
Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0