|
198611
|
7.8 |
HIGH
Local
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the desktop application used to connect to the device suffers from a stack ov…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10720
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198612
|
6.5 |
MEDIUM
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that the device has default Wi-Fi credentials that are exactly the same for every …
|
CWE-200
Information Exposure
|
CVE-2017-10719
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198613
|
6.5 |
MEDIUM
Network
|
ishekar
|
endoscope_camera_firmware
|
Recently it was discovered as a part of the research on IoT devices in the most recent firmware for Shekar Endoscope that any malicious user connecting to the device can change the default SSID and p…
|
CWE-255
Credentials Management
|
CVE-2017-10718
|
2024-11-21 12:06 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198614
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware
|
A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU,…
|
NVD-CWE-noinfo
|
CVE-2017-11004
|
2024-11-21 12:06 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198615
|
7.5 |
HIGH
Network
|
zte
|
zxiptv-ucm_firmware
|
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the d…
|
CWE-89
SQL Injection
|
CVE-2017-10937
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198616
|
7.5 |
HIGH
Network
|
zte
|
zxcdn-sns_firmware
|
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclos…
|
CWE-89
SQL Injection
|
CVE-2017-10936
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198617
|
7.2 |
HIGH
Network
|
zte
|
zxr10_1800-2s_firmware
|
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
|
NVD-CWE-noinfo
|
CVE-2017-10935
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198618
|
9.8 |
CRITICAL
Network
|
zte
|
zxiptv-epg_firmware
|
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserializatio…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-10934
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198619
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_835_…
|
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 835, a Use After…
|
CWE-416
Use After Free
|
CVE-2017-11011
|
2024-11-21 12:06 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198620
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.
|
NVD-CWE-noinfo
|
CVE-2017-11010
|
2024-11-21 12:06 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|