VARIoT IoT vulnerabilities database

Affected products: vendor, model and version
CWE format is 'CWE-number'. Threat type can be: remote or local
Look up free text in title and description

VAR-201904-0754 CVE-2018-4195 Safari User interface mismatch vulnerability CVSS V2: 4.3
CVSS V3: 6.5
Severity: MEDIUM
An inconsistent user interface issue was addressed with improved state management. This issue affected versions prior to Safari 12. Apple Safari is prone to a security-bypass vulnerability. Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions. Apple Safari is a web browser developed by Apple (Apple), and is the default browser included with MacOSX and iOS operating systems. Attackers can use malicious websites to exploit this vulnerability to forge user interfaces. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 APPLE-SA-2018-9-24-3 Additional information for APPLE-SA-2018-9-17-4 Safari 12 Safari 12 addresses the following: Safari Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: A user may be unable to delete browsing history items Description: Clearing a history item may not clear visits with redirect chains. CVE-2018-4329: Hugo S. CVE-2018-4195: xisigr of Tencent's Xuanwu Lab (www.tencent.com) Security Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: A malicious website may be able to exfiltrate autofilled data in Safari Description: A logic issue was addressed with improved state management. CVE-2018-4307: Rafay Baloch of Pakistan Telecommunications Authority WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Unexpected interaction causes an ASSERT failure Description: A memory corruption issue was addressed with improved validation. CVE-2018-4191: found by OSS-Fuzz Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Cross-origin SecurityErrors includes the accessed frame's origin Description: The issue was addressed by removing origin information. CVE-2018-4311: Erling Alf Ellingsen (@steike) Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A memory corruption issue was addressed with improved state management. CVE-2018-4316: crixer, Hanming Zhang (@4shitak4) of Qihoo 360 Vulcan Team Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: Multiple memory corruption issues were addressed with improved memory handling. CVE-2018-4299: Samuel GroI2 (saelo) working with Trend Micro's Zero Day Initiative CVE-2018-4323: Ivan Fratric of Google Project Zero CVE-2018-4328: Ivan Fratric of Google Project Zero CVE-2018-4358: @phoenhex team (@bkth_ @5aelo @_niklasb) working with Trend Micro's Zero Day Initiative CVE-2018-4359: Samuel GroA (@5aelo) Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: A malicious website may cause unexepected cross-origin behavior Description: A cross-origin issue existed with "iframe" elements. This was addressed with improved tracking of security origins. CVE-2018-4319: John Pettitt of Google Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: A malicious website may be able to execute scripts in the context of another website Description: A cross-site scripting issue existed in Safari. CVE-2018-4309: an anonymous researcher working with Trend Micro's Zero Day Initiative Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Processing maliciously crafted web content may lead to arbitrary code execution Description: A use after free issue was addressed with improved memory management. CVE-2018-4197: Ivan Fratric of Google Project Zero CVE-2018-4306: Ivan Fratric of Google Project Zero CVE-2018-4312: Ivan Fratric of Google Project Zero CVE-2018-4314: Ivan Fratric of Google Project Zero CVE-2018-4315: Ivan Fratric of Google Project Zero CVE-2018-4317: Ivan Fratric of Google Project Zero CVE-2018-4318: Ivan Fratric of Google Project Zero Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: A malicious website may exfiltrate image data cross-origin Description: A cross-site scripting issue existed in Safari. CVE-2018-4345: an anonymous researcher Entry added September 24, 2018 WebKit Available for: macOS Sierra 10.12.6, macOS High Sierra 10.13.6, macOS Mojave 10.14 Impact: Unexpected interaction causes an ASSERT failure Description: A memory consumption issue was addressed with improved memory handling. CVE-2018-4361: found by Google OSS-Fuzz Entry added September 24, 2018 Additional recognition WebKit We would like to acknowledge Cary Hartline, Hanming Zhang from 360 Vuclan team, Tencent Keen Security Lab working with Trend Micro's Zero Day Initiative, and Zach Malone of CA Technologies for their assistance. Installation note: Safari 12 may be obtained from the Mac App Store. Information will also be posted to the Apple Security Updates web site: https://support.apple.com/kb/HT201222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEDNXJVNCJJEAVmJdZeC9tht7TK3EFAlupFUIACgkQeC9tht7T K3EOzBAAr4Kr9hZVKV603mOTE9cq6boEBYJLYJUN2/VjLzBPYWYr/e8tPg0P1EWr i67b/0pWifR6A73F53oCxMzdumfwC4by2n106ABrx5KPYmbz5YBk8X/YEEWokBdK zK/AJpQo768pTUIxlVuhIOsCLOieMRX3kiPWIg10WeIEggEnyavK9/emNyUu08GV AXviCAz2vohBgG0pAvgKt2HD/yTxG2n+gdP9krOT9mMh0aH1tTlZ8107cF2bTWwv yZw9LSCELre6cKOx4iDaY+vpPWGXwI+8+6hXYqKjNBomgJhLeQVqIdBo29IM0HTO FZcyrQ5djoNDl8ZfGUAwFtyDhD4Fmdb/JyDdvLXME/GL2fPWG8hqDS5EGU/cNIus ugQv/zsm6pXqLWt+sxbP5lU4Uuwfkw4H7HwwBxoE04ufGfxurEBgTIIQn+KwYg9J ODrdoqsIDThOtqQHxzp0//+rs0hg49jGm4P8eSG86Oycoyw/Q9/pzCKeQGazfyfF cTNX3wsZA84RVbHLVWbp0ZnYhVrH1iL61ipzH2hDTUbjelvv4u4pN6flIM6Kw9uN J5bYuFOXzv61bxMe8fdAlZixqFXqJ5oNBTZOdaicZEKmfRTTh4p1BLTWcFSRbp7K wCXqHSwmD7RjGr0Qbr/CvJFb/+kOrzQIHX7sCR6ZIusZPLpTYXI= =4ySP -----END PGP SIGNATURE-----
VAR-201809-1333 No CVE High Password Network Firmware Router Has Weak Password Vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Shanghai Guoyun Information Technology Co., Ltd. is a provider of intelligent network products and services. A high-level network firmware router has a weak password vulnerability. Allow attackers to brute force account passwords, log in to the system, and obtain sensitive information.
VAR-201809-0769 CVE-2018-17068 D-Link DIR-816 A2 Command injection vulnerabilities in devices CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is acquired, information is falsified, and denial of service (DoS) May be in a state. D-LinkDIR-816A2 is a wireless router product of D-Link. There is a command injection vulnerability in D-LinkDIR-816A21.10B05. This vulnerability is caused by the program using the 'sendNum' parameter value when building the 'ping-c%s...' command
VAR-201809-0767 CVE-2018-17066 D-Link DIR-816 A2 Command injection vulnerability in devices CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816 is a home router product from Friends of the company. A command injection vulnerability exists in D-LinkDIR-816A21.10B05. This vulnerability is caused by the program using the \342\200\230datetime\342\200\231 parameter value to construct the \342\200\230date-s\342\200\235%s\342\200\235 command, which can be exploited by an attacker
VAR-201809-0765 CVE-2018-17064 D-Link DIR-816 A2 Command injection vulnerability in devices CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816 is a home router product from Friends of the company. A command injection vulnerability exists in D-LinkDIR-816A21.10B05, which is caused by a program using HTTP requests to build commands that an attacker can use to inject commands. The /goform/sylogapply in D-Link DIR-816 A2 version 1.10 B05 has an operating system command injection vulnerability
VAR-201809-0768 CVE-2018-17067 D-Link DIR-816 A2 Device buffer error vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address. D-Link DIR-816 A2 The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A stack buffer overflow vulnerability exists in D-LinkDIR-816A21.10B05
VAR-201809-0764 CVE-2018-17063 D-Link DIR-816 A2 Command injection vulnerability in devices CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters. D-Link DIR-816 A2 The device contains a command injection vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A command injection vulnerability exists in D-LinkDIR-816A21.10B05, which is caused by a program using HTTP requests to build commands that an attacker can use to send arbitrary code to execute arbitrary code on the system. The /goform/NTPSyncWithHost in D-Link DIR-816 A2 version 1.10 B05 has an operating system command injection vulnerability
VAR-201809-0766 CVE-2018-17065 D-Link DIR-816 A2 Device buffer error vulnerability CVSS V2: 10.0
CVSS V3: 9.8
Severity: CRITICAL
An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address. D-Link DIR-816 A2 The device contains a buffer error vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. D-LinkDIR-816A2 is a wireless router product of D-Link. A stack-based buffer overflow vulnerability exists in D-Link DIR-816 A2 version 1.10 B05
VAR-201809-0942 CVE-2018-16242 Hangzhou Luoping Smart Locker Access control vulnerability CVSS V2: 2.9
CVSS V3: 5.3
Severity: MEDIUM
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol. Hangzhou Luoping Smart Locker Contains an access control vulnerability.Information may be tampered with. oBike is a bicycle sharing system of Singapore oBike Company. There is a security flaw in oBike
VAR-201809-1341 No CVE Hikvision hik-connect.com Certification Vulnerability CVSS V2: 6.4
CVSS V3: -
Severity: MEDIUM
Hikvision is a video-centric IoT solution provider. Hikvisionhik-connect.com has an authentication vulnerability. An attacker could exploit the vulnerability to change the cookie value to someone else's user ID that would result in logging in with that user.
VAR-201809-1207 No CVE Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18910) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has a denial-of-service vulnerability. An attacker can construct a specific network packet without authorization, and the vulnerability can cause the PLC to deny service
VAR-201809-1208 No CVE Hollysys LE5109L PLC has remote controller removal vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has a remote controller removal vulnerability. An attacker can remotely clear all programs and configuration information of the controller in the PLC by constructing a specific modbus data packet
VAR-201809-1214 No CVE Hollysys LE5109L PLC has remote control vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has a remote control vulnerability. An attacker can use the vulnerability to cause the PLC to be remotely controlled by constructing a specific private protocol data packet
VAR-201809-1196 No CVE Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18909) CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has a denial of service vulnerability. An attacker can use the vulnerability to cause the PLC to deny service by constructing specific private protocol data packets
VAR-201809-1193 No CVE Hollysys LE5109L PLC Has Arbitrary Program Clearance Vulnerabilities CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has an arbitrary program removal vulnerability. An attacker can construct a specific network data packet by unauthorized use. The vulnerability can cause the program in the PLC controller to be maliciously removed
VAR-201809-1213 No CVE Hollysys LE5109L PLC has arbitrary memory tampering vulnerability CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has an arbitrary memory tampering vulnerability. An attacker can use the vulnerability to remotely tamper with PLC register values by constructing a specific modbus data packet
VAR-201809-1195 No CVE Hollysys LE5109L PLC Denial of Service Vulnerability (CNVD-2018-18906) CVSS V2: 7.8
CVSS V3: -
Severity: HIGH
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has a denial of service vulnerability. An attacker can use the vulnerability to cause the PLC to be remotely controlled by constructing a specific private protocol data packet. PLC Be remotely controlled
VAR-201809-1194 No CVE Hollysys LE5109L PLC has an arbitrary memory read vulnerability CVSS V2: 5.0
CVSS V3: -
Severity: MEDIUM
Hollysys Group is a professional automation company integrating R & D, production, sales and technical services. Hollysys LE5109L PLC has an arbitrary memory read vulnerability. An attacker can construct a specific modbus data packet and use the vulnerability to cause any register value in the PLC to be read arbitrarily
VAR-201809-1114 CVE-2018-7929 Huawei Mate RS Vulnerability related to access control in smartphones CVSS V2: 4.6
CVSS V3: 6.8
Severity: MEDIUM
Huawei Mate RS smartphones with the versions before NEO-AL00D 8.1.0.167(C786) have a lock-screen bypass vulnerability. An attacker could unlock and use the phone through certain operations. Huawei Mate RS Smartphones have access control vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state
VAR-201809-0093 CVE-2018-12086 OPC UA Application buffer error vulnerability CVSS V2: 5.0
CVSS V3: 7.5
Severity: HIGH
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests. OPC UA The application contains a buffer error vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. OPC UA applications is a platform-independent service-oriented unified architecture application from the OPC (OLE for Process Control) Foundation. SAP Plant Connectivity is prone to multiple denial-of-service vulnerabilities. Attackers can exploit these issues to cause denial-of-service conditions, denying service to legitimate users. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4359-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff December 27, 2018 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : wireshark CVE ID : CVE-2018-12086 CVE-2018-18225 CVE-2018-18226 CVE-2018-18227 CVE-2018-19622 CVE-2018-19623 CVE-2018-19624 CVE-2018-19625 CVE-2018-19626 CVE-2018-19627 CVE-2018-19628 Multiple vulnerabilities have been discovered in Wireshark, a network protocol analyzer, which could result in denial of service or the execution of arbitrary code. For the stable distribution (stretch), these problems have been fixed in version 2.6.5-1~deb9u1. We recommend that you upgrade your wireshark packages. For the detailed security status of wireshark please refer to its security tracker page at: https://security-tracker.debian.org/tracker/wireshark Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAlwk6BkACgkQEMKTtsN8 TjZeQg//epVGPGld0oOwn+9I3rD4C0GZMKOCtHW7xR5x+YKMntG7VzLAcSv33EEi hDj2V0ZFr8NIWab0qtTun4BQMMZ7J80hy//hFr9OcAu1apdG38KW0drMG2/sBBL8 HH6ndYLgrtxqbtmqNBxPrabq+Fj01jlCwTmrd9ig0/ZQOSlRbfM+Snfjxpmwlsgl x8ZoWi9TPD+ILZe2V6m4w81aR6FF3e540W6ADAJ233gpJbQ5mHvOlX1tJzPDTQOe 8KqGZ4FhYan7wO6u41gRHCtqMEymh1LRc+zTzeow9jNs7u83GRMT4bqerCkVKI3W JPr1+EbYNyZApWYzeigomGQSXiTMKvURm1NxevhhZW81y0xJgHS7q7gsvu1zitQl hUqA9r/F74Ts6uru+ubknk1OeA0UrY/ZXVMZUgsYAZ4vFvcvPzK2gqZoBMI0tAy5 PxAnScxMalJA8faUsjl/0O5URG/Sv0MKzLo9hexog7dE/vH0j5iuZqbhT7UDmvdL B2l7XwVlZCKI5pLgNhCqBSxf3mL7sr/wzpPF2YYuFGTGQ+doTy6C9GL1Z/J/087w Hbd7i5Pnu+GM+SXswSIsDNsq4fMYHrBJvJz+w2YWImdKuR9+fKSPAtdto/id5t9m s61uMXB9ul+5H0pw19otWQUvJog5qcCrTFLEe5F+CMUJDjWDqrY=xlYz -----END PGP SIGNATURE-----