Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown
CVE-2024-32876
Disclosure Date: April 24, 2024 (last updated April 25, 2024)
NewPipe is an Android app for video streaming written in Java. It supports exporting and importing backups, as a way to let users move their data to a new device effortlessly. However, in versions 0.13.4 through 0.26.1, importing a backup file from an untrusted source could have resulted in Arbitrary Code Execution. This is because backups are serialized/deserialized using Java's Object Serialization Stream Protocol, which can allow constructing any class in the app, unless properly restricted.
To exploit this vulnerability, an attacker would need to build a backup file containing the exploit, and then persuade a user into importing it. During the import process, the malicious code would be executed, possibly crashing the app, stealing user data from the NewPipe app, performing nasty actions through Android APIs, and attempting Android JVM/Sandbox escapes through vulnerabilities in the Android OS.
The attack can take place only if the user imports a malicious backup file, so an atta…
0
Attacker Value
Unknown
CVE-2020-20189
Disclosure Date: December 14, 2020 (last updated February 22, 2025)
SQL Injection vulnerability in NewPK 1.1 via the title parameter to admin\newpost.php.
0
Attacker Value
Unknown
CVE-2017-7919
Disclosure Date: July 03, 2017 (last updated November 26, 2024)
An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL).
0
Attacker Value
Unknown
CVE-2015-7772
Disclosure Date: November 20, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted URL that triggers WebView anchor attachment in an applican application, a different vulnerability than CVE-2015-7771.
0
Attacker Value
Unknown
CVE-2015-7771
Disclosure Date: November 20, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the runtime engine in the Newphoria applican framework before 1.13.0 for Android and iOS allows remote attackers to inject arbitrary web script or HTML via a crafted SSID that is encountered by an applican application, a different vulnerability than CVE-2015-7772.
0
Attacker Value
Unknown
CVE-2015-5633
Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The Newphoria Auction Camera application for iOS and before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5637
Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The Newphoria Photon application before 1.2 for Android allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5636
Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The Newphoria Reversi application before 1.0.3 for Android and before 1.2 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5635
Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The Newphoria Koritore application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-5632
Disclosure Date: September 20, 2015 (last updated October 05, 2023)
The runtime engine in the Newphoria applican framework before 1.12.3 for Android and before 1.12.2 for iOS allows attackers to bypass a whitelist.xml URL whitelist protection mechanism and obtain API access via unspecified vectors.
0