Show filters
113 Total Results
Displaying 71-80 of 113
Sort by:
Attacker Value
Unknown
CVE-2018-8844
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request.
0
Attacker Value
Unknown
CVE-2018-8848
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software, upon installation, sets incorrect permissions for an object that exposes it to an unintended actor.
0
Attacker Value
Unknown
CVE-2018-8852
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. When authenticating a user or otherwise establishing a new user session, the software gives an attacker the opportunity to steal authenticated sessions without invalidating any existing session identifier.
0
Attacker Value
Unknown
CVE-2018-8842
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The software transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. The Philips e-Alert communication channel is not encrypted which could therefore lead to disclosure of personal contact information and application login credentials from within the same subnet.
0
Attacker Value
Unknown
CVE-2018-14803
Disclosure Date: September 26, 2018 (last updated November 27, 2024)
Philips e-Alert Unit (non-medical device), Version R2.1 and prior. The Philips e-Alert contains a banner disclosure vulnerability that could allow attackers to obtain extraneous product information, such as OS and software components, via the HTTP response header that is normally not available to the attacker, but might be useful information in an attack.
0
Attacker Value
Unknown
CVE-2018-14789
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 3.1 or prior and Xcelera Version 4.1 or prior), an unquoted search path or element vulnerability has been identified, which may allow an attacker to execute arbitrary code and escalate their level of privileges.
0
Attacker Value
Unknown
CVE-2018-14801
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, an attacker with both the superuser password and physical access can enter the superuser password that can be used to access and modify all settings on the device, as well as allow the user to reset existing passwords.
0
Attacker Value
Unknown
CVE-2018-14787
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
In Philips' IntelliSpace Cardiovascular (ISCV) products (ISCV Version 2.x or prior and Xcelera Version 4.1 or prior), an attacker with escalated privileges could access folders which contain executables where authenticated users have write permissions, and could then execute arbitrary code with local administrative permissions.
0
Attacker Value
Unknown
CVE-2018-14799
Disclosure Date: August 22, 2018 (last updated November 27, 2024)
In Philips PageWriter TC10, TC20, TC30, TC50, TC70 Cardiographs, all versions prior to May 2018, the PageWriter device does not sanitize data entered by user. This can lead to buffer overflow or format string vulnerabilities.
0
Attacker Value
Unknown
Applications developed using the Portrait Display SDK, versions 2.30 through 2.…
Disclosure Date: July 24, 2018 (last updated November 27, 2024)
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe with NT AUTHORITY/SYSTEM permissions. This component is also read/writable by all Authenticated Users. This allows local authenticated attackers to run arbitrary code with SYSTEM privileges. The following applications have been identified by Portrait Displays as affected: Fujitsu DisplayView Click: Version 6.0 and 6.01. The issue was fixed in Version 6.3. Fujitsu DisplayView Click Suite: Version 5. The issue is addressed by patch in Version 5.9. HP Display Assistant: Version 2.1. The issue was fixed in Version 2.11. HP My Display: Version 2.0. The issue was fixed in Version 2.1. Philips Smart Control Premium: Versions 2.23, 2.25. The issue was fixed in Version 2.26.
0