• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2019-9681
Dahuasecurity, Ipc-hfw5x2x, Ipc-hfw5x2x Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2020-08-24
N/A
5.3 MEDIUM
Online upgrade information in some firmware packages of Dahua products is not encrypted. Attackers can obtain this information by analyzing firmware packages by specific means. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
CVE-2019-9680
Dahuasecurity, Ipc-hfw5x2x, Ipc-hfw5x2x Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2021-07-21
N/A
5.3 MEDIUM
Some Dahua products have information leakage issues. Attackers can obtain the IP address and device model information of the device by constructing malicious data packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
CVE-2019-9679
Dahuasecurity, Ipc-hfw5x2x, Ipc-hfw5x2x Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-09-19
N/A
8.8 HIGH
Some of Dahua's Debug functions do not have permission separation. Low-privileged users can use the Debug function after logging in. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18,2019.
CVE-2019-9678
Dahuasecurity, Ipc-hfw5x2x, Ipc-hfw5x2x Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2021-07-21
N/A
7.5 HIGH
Some Dahua products have the problem of denial of service during the login process. An attacker can cause a device crashed by constructing a malicious packet. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
CVE-2019-9677
Dahuasecurity, Ipc-hfw5x2x, Ipc-hfw5x2x Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-09-19
N/A
9.8 CRITICAL
The specific fields of CGI interface of some Dahua products are not strictly verified, an attacker can cause a buffer overflow by constructing malicious packets. Affected products include: IPC-HDW1X2X,IPC-HFW1X2X,IPC-HDW2X2X,IPC-HFW2X2X,IPC-HDW4X2X,IPC-HFW4X2X,IPC-HDBW4X2X,IPC-HDW5X2X,IPC-HFW5X2X for versions which Build time is before August 18, 2019.
CVE-2019-9676
Dahuasecurity, Ipc-hfw2xxx, Ipc-hfw2xxx Firmware
Ipc-hfw1xxx_firmware, Ipc-hfw1xxx, Ipc-hdw1xxx_firmware, Ipc-hdw1xxx, Ipc-hfw2xxx_firmware, Ipc-hfw2xxx, Ipc-hdw1x2x_firmware, Ipc-hdw1x2x, Ipc-hfw1x2x_firmware, Ipc-hfw1x2x
2019-06-17
N/A
7.8 HIGH
Buffer overflow vulnerability found in some Dahua IP Camera devices IPC-HFW1XXX,IPC-HDW1XXX,IPC-HFW2XXX Build before 2018/11. The vulnerability exits in the function of redirection display for serial port printing information, which can not be used by product basic functions. After an attacker logs in locally, this vulnerability can be exploited to cause device restart or arbitrary code execution. Dahua has identified the corresponding security problems in the static code auditing process, so it has gradually deleted this function, which is no longer available in the newer devices and softwares. Dahua has released versions of the affected products to fix the vulnerability.
CVE-2019-9675
2019-06-03
N/A
8.1 HIGH
** DISPUTED ** An issue was discovered in PHP 7.x before 7.1.27 and 7.3.x before 7.3.3. phar_tar_writeheaders_int in ext/phar/tar.c has a buffer overflow via a long link value. NOTE: The vendor indicates that the link value is used only when an archive contains a symlink, which currently cannot happen: "This issue allows theoretical compromise of security, but a practical attack is usually impossible."
CVE-2019-9674
2020-07-27
N/A
7.5 HIGH
Lib/zipfile.py in Python through 3.7.2 allows remote attackers to cause a denial of service (resource consumption) via a ZIP bomb.
CVE-2019-9673
2019-06-10
N/A
8.8 HIGH
Freenet 1483 has a MIME type bypass that allows arbitrary JavaScript execution via a crafted Freenet URI.
CVE-2019-9670
2021-06-26
N/A
9.8 CRITICAL
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
« Previous 1 … 5,069 5,070 5,071 5,072 5,073 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE