CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
20007_office_system, 27mhz_wireless_keyboard, 365_apps, 3d_builder, 3d_viewer, Access, Accessibility_insights_for_android, Accessibility_insights_for_web, Access_multilingual_user_interface_pack, Active_directory
2020-08-24
N/A
5.5 MEDIUM
An elevation of privilege vulnerability exists when the .NET Framework common language runtime (CLR) allows file creation in arbitrary locations, aka '.NET Framework Elevation of Privilege Vulnerability'.
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause a denial of service (application crash) by replacing an emoji file (under the /sdcard/tencent/MicroMsg directory) with a crafted .wxgf file. The content of the replacement must be derived from the phone's IMEI. The crash occurs upon receiving a message that contains the replaced emoji.
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2019-04-23
N/A
9.8 CRITICAL
apply.cgi on the TRENDnet TEW-632BRP 1.010B32 router has a buffer overflow via long strings to the SOAPACTION:HNAP1 interface.
Securview_wireless_internet_camera, Securview_wireless_internet_camera_activex_control, Teg-30102ws, Teg-30102ws_firmware, Tew-632brp, Tew-632brp_firmware, Tew-651br, Tew-651br_firmware, Tew-652br, Tew-652br_firmware
2021-07-21
N/A
9.8 CRITICAL
system.cgi on TRENDnet TV-IP110WN cameras has a buffer overflow caused by an inadequate source-length check before a strcpy operation in the respondAsp function. Attackers can exploit the vulnerability by using the languse parameter with a long string. This affects 1.2.2 build 28, 64, 65, and 68.
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2019-05-06
N/A
8.8 HIGH
A CSRF issue was discovered on Intelbras IWR 3000N 1.5.0 devices, leading to complete control of the router, as demonstrated by v1/system/user.
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2020-08-24
N/A
7.5 HIGH
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. A malformed login request allows remote attackers to cause a denial of service (reboot), as demonstrated by JSON misparsing of the ""} string to v1/system/login.
Iwr_3000n_firmware, Iwr_3000n, Wrn_150_firmware, Wrn_150, Iwr_1000n_firmware, Iwr_1000n, Wrn_240_firmware, Wrn_240, Action_rf_1200_firmware, Action_rf_1200
2019-04-22
N/A
8.8 HIGH
An issue was discovered on Intelbras IWR 3000N 1.5.0 devices. When the administrator password is changed from a certain client IP address, administrative authorization remains available to any client at that IP address, leading to complete control of the router.
An issue was discovered in Artifex MuJS 1.0.5. It has unlimited recursion because the match function in regexp.c lacks a depth check.
An issue was discovered in Artifex MuJS 1.0.5. jscompile.c can cause a denial of service (invalid stack-frame jump) because it lacks an ENDTRY opcode call.
An issue was discovered in Artifex MuJS 1.0.5. The Number#toFixed() and numtostr implementations in jsnumber.c have a stack-based buffer overflow.
