Show filters
274 Total Results
Displaying 51-60 of 274
Sort by:
Attacker Value
Unknown

CVE-2022-39861

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Unprotected Receiver in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to record video without camera privilege.
Attacker Value
Unknown

CVE-2022-39858

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Path traversal vulnerability in AtBroadcastReceiver in FactoryCamera prior to version 3.5.51 allows attackers to write arbitrary file as FactoryCamera privilege.
Attacker Value
Unknown

CVE-2022-39857

Disclosure Date: October 07, 2022 (last updated February 24, 2025)
Improper access control vulnerability in CameraTestActivity in FactoryCameraFB prior to version 3.5.51 allows attackers to access broadcasting Intent as system uid privilege.
Attacker Value
Unknown

CVE-2022-40784

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Unlimited strcpy on user input when setting a locale file leads to stack buffer overflow in mIPC camera firmware 5.3.1.2003161406.
Attacker Value
Unknown

CVE-2022-40785

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
Unsanitized input when setting a locale file leads to shell injection in mIPC camera firmware 5.3.1.2003161406. This allows an attacker to gain remote code execution on cameras running the firmware when a victim logs into a specially crafted mobile app.
Attacker Value
Unknown

CVE-2022-36832

Disclosure Date: August 05, 2022 (last updated February 24, 2025)
Improper access control vulnerability in WebApp in Cameralyzer prior to versions 3.2.22, 3.3.22, 3.4.22 and 3.5.51 allows attackers to access external storage as Cameralyzer privilege.
Attacker Value
Unknown

CVE-2022-33712

Disclosure Date: July 12, 2022 (last updated February 24, 2025)
Intent redirection vulnerability using implict intent in Camera prior to versions 12.0.01.64 ,12.0.3.23, 12.0.0.98, 12.0.6.11, 12.0.3.19 in Android S(12) allows attacker to get sensitive information.
Attacker Value
Unknown

CVE-2022-30620

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
On Cellinx Camera with guest enabled, attacker with web access can elevate privileges to administrative: "1" to "0" privileges by changing the following cookie values from "is_admin", "showConfig". Administrative Privileges which allows changing various configuration in the camera.
Attacker Value
Unknown

CVE-2022-30621

Disclosure Date: July 06, 2022 (last updated February 24, 2025)
Allows a remote user to read files on the camera's OS "GetFileContent.cgi". Reading arbitrary files on the camera's OS as root user.
Attacker Value
Unknown

CVE-2018-17240

Disclosure Date: June 10, 2022 (last updated February 23, 2025)
There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).