|
209731
|
8.1 |
HIGH
Adjacent
|
depstech
|
wifi_digital_microscope_3_firmware
|
DEPSTECH WiFi Digital Microscope 3 allows remote attackers to change the SSID and password, and demand a ransom payment from the rightful device owner, because there is no way to reset to Factory Def…
|
CWE-862
Missing Authorization
|
CVE-2020-12734
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209732
|
7.5 |
HIGH
Network
|
depstech
|
wifi_digital_microscope_3_firmware
|
Certain Shenzhen PENGLIXIN components on DEPSTECH WiFi Digital Microscope 3, as used by Shekar Endoscope, allow a TELNET connection with the molinkadmin password for the molink account.
|
CWE-863
Incorrect Authorization
|
CVE-2020-12733
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209733
|
6.5 |
MEDIUM
Adjacent
|
depstech
|
wifi_digital_microscope_3_firmware
|
DEPSTECH WiFi Digital Microscope 3 has a default SSID of Jetion_xxxxxxxx with a password of 12345678.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2020-12732
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209734
|
7.5 |
HIGH
Network
|
magicsmotion
|
flamingo_2_firmware
|
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-12731
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209735
|
5.3 |
MEDIUM
Adjacent
|
magicsmotion
|
flamingo_2_firmware
|
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12730
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209736
|
4.6 |
MEDIUM
Physics
|
magicsmotion
|
flamingo_2_firmware
|
MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors.
|
NVD-CWE-Other
|
CVE-2020-12729
|
2024-11-21 14:00 |
2021-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209737
|
5.5 |
MEDIUM
Local
|
amd
|
radeon_pro_software radeon_software
|
A heap information leak/kernel pool address disclosure vulnerability in the AMD Graphics Driver for Windows 10 may lead to KASLR bypass.
|
CWE-200
Information Exposure
|
CVE-2020-12987
|
2024-11-21 14:00 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209738
|
7.8 |
HIGH
Local
|
amd
|
radeon_pro_software radeon_software
|
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may cause arbitrary code execution in the kernel, leading to escalation of privilege or denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2020-12986
|
2024-11-21 14:00 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209739
|
7.5 |
HIGH
Network
|
amd
|
epyc_7001_firmware epyc_7002_firmware epyc_7003_firmware epyc_7232p_firmware epyc_7251_firmware epyc_7252_firmware epyc_7261_firmware epyc_7262_firmware epyc_7272_firmware …
|
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
|
NVD-CWE-noinfo
|
CVE-2020-12988
|
2024-11-21 14:00 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209740
|
7.8 |
HIGH
Local
|
amd
|
radeon_pro_software radeon_software
|
An insufficient pointer validation vulnerability in the AMD Graphics Driver for Windows 10 may lead to escalation of privilege or denial of service.
|
CWE-20
Improper Input Validation
|
CVE-2020-12985
|
2024-11-21 14:00 |
2021-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|