Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-45504
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.
0
Attacker Value
Unknown
CVE-2023-6324
Disclosure Date: May 15, 2024 (last updated February 12, 2025)
ThroughTek Kalay SDK uses a predictable PSK value in the DTLS session when encountering an unexpected PSK identity
0
Attacker Value
Unknown
CVE-2023-6323
Disclosure Date: May 15, 2024 (last updated February 12, 2025)
ThroughTek Kalay SDK does not verify the authenticity of received messages, allowing an attacker to impersonate an authoritative server.
0
Attacker Value
Unknown
CVE-2023-6322
Disclosure Date: May 15, 2024 (last updated February 12, 2025)
A stack-based buffer overflow vulnerability exists in the message parsing functionality of the Roku Indoor Camera SE version 3.0.2.4679 and Wyze Cam v3 version 4.36.11.5859. A specially crafted message can lead to stack-based buffer overflow. An attacker can make authenticated requests to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2020-28437
Disclosure Date: August 02, 2022 (last updated October 08, 2023)
This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.
0
Attacker Value
Unknown
CVE-2022-27152
Disclosure Date: April 08, 2022 (last updated October 07, 2023)
Roku devices running RokuOS v9.4.0 build 4200 or earlier that uses a Realtek WiFi chip is vulnerable to Arbitrary file modification.
0
Attacker Value
Unknown
CVE-2020-7634
Disclosure Date: April 06, 2020 (last updated February 21, 2025)
heroku-addonpool through 0.1.15 is vulnerable to Command Injection.
0
Attacker Value
Unknown
CVE-2018-11314
Disclosure Date: July 03, 2018 (last updated November 08, 2023)
The External Control API in Roku and Roku TV products allow unauthorized access via a DNS Rebind attack. This can result in remote device control and privileged device and network information to be exfiltrated by an attacker.
0