|
255961
|
5.5 |
MEDIUM
Local
|
qualcomm
|
ipq8074_firmware mdm9206_firmware mdm9607_firmware mdm9635m_firmware mdm9650_firmware mdm9655_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware
|
A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU,…
|
NVD-CWE-noinfo
|
CVE-2017-11004
|
2024-11-21 12:06 |
2019-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255962
|
7.5 |
HIGH
Network
|
zte
|
zxiptv-ucm_firmware
|
SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the d…
|
CWE-89
SQL Injection
|
CVE-2017-10937
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255963
|
7.5 |
HIGH
Network
|
zte
|
zxcdn-sns_firmware
|
SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclos…
|
CWE-89
SQL Injection
|
CVE-2017-10936
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255964
|
7.2 |
HIGH
Network
|
zte
|
zxr10_1800-2s_firmware
|
All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.
|
NVD-CWE-noinfo
|
CVE-2017-10935
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255965
|
9.8 |
CRITICAL
Network
|
zte
|
zxiptv-epg_firmware
|
All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserializatio…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-10934
|
2024-11-21 12:06 |
2018-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255966
|
9.8 |
CRITICAL
Network
|
qualcomm
|
mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_425_firmware sd_430_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_835_…
|
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 835, a Use After…
|
CWE-416
Use After Free
|
CVE-2017-11011
|
2024-11-21 12:06 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255967
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.
|
NVD-CWE-noinfo
|
CVE-2017-11010
|
2024-11-21 12:06 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255968
|
8.8 |
HIGH
Adjacent
|
corega
|
cg-wgr_1200_firmware
|
Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to bypass authentication and change the login password via unspecified vectors.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2017-10854
|
2024-11-21 12:06 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255969
|
8.8 |
HIGH
Adjacent
|
corega
|
cg-wgr_1200_firmware
|
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10853
|
2024-11-21 12:06 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255970
|
8.8 |
HIGH
Adjacent
|
corega
|
cg-wgr_1200_firmware
|
Buffer overflow in Corega CG-WGR1200 firmware 2.20 and earlier allows an attacker to execute arbitrary code via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-10852
|
2024-11-21 12:06 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|