CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2020-08-24
N/A
5.3 MEDIUM
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2021-07-21
N/A
5.3 MEDIUM
Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-09-19
N/A
8.8 HIGH
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2021-07-21
N/A
7.5 HIGH
Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-09-19
N/A
9.8 CRITICAL
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-06-17
N/A
7.8 HIGH
Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions. After an attacker logs in locally, this vulnerability can be exploited to cause device restart or arbitrary code execution. Dahua has identified the corresponding security problems in the static code auditing process, so it has gradually deleted this function, which is no longer available in the newer devices and softwares. Dahua has released versions of the affected products to fix the vulnerability.
** DISPUTED ** An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
