VARIoT IoT vulnerabilities database
| VAR-202112-0136 | CVE-2021-37042 | Huawei Input validation vulnerability in smartphone products |
CVSS V2: 6.4 CVSS V3: 9.1 Severity: CRITICAL |
There is an Improper verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause out-of-bounds read. Huawei A vulnerability related to input validation exists in smartphone products.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202112-0133 | CVE-2021-37055 | Huawei Vulnerabilities in smartphone products |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
There is a Logic bypass vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may allow attempts to obtain certain device information. Huawei Smartphone products have unspecified vulnerabilities.Information may be obtained
| VAR-202112-0246 | CVE-2021-37068 | Huawei Vulnerabilities in smartphones |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
There is a Resource Management Errors vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to denial of Service Attacks. Huawei Smartphones have unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state
| VAR-202112-0135 | CVE-2021-37046 | Huawei Vulnerability related to lack of memory release after expiration in smartphone products |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
There is a Memory leak vulnerability with the codec detection module in Huawei Smartphone.Successful exploitation of this vulnerability may cause the device to restart due to memory exhaustion. Huawei A vulnerability related to lack of freeing memory after expiration exists in smartphone products.Service operation interruption (DoS) It may be in a state
| VAR-202112-0134 | CVE-2021-37047 | Huawei Input validation vulnerability in smartphone products |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
There is an Input verification vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may cause some services to restart. Huawei A vulnerability related to input validation exists in smartphone products.Service operation interruption (DoS) It may be in a state
| VAR-202112-1083 | No CVE | KingView (KingView) has a binary vulnerability |
CVSS V2: 4.9 CVSS V3: - Severity: MEDIUM |
KingView is an industrial automation configuration software produced by Beijing Yakong Technology Development Co., Ltd.
There is a binary vulnerability in KingView, which can be exploited by an attacker to cause the program to crash.
| VAR-202112-1082 | No CVE | TOTOLINK EX200 has a command execution vulnerability |
CVSS V2: 8.3 CVSS V3: - Severity: HIGH |
TOTOLINK EX200 is a wireless extender.
TOTOLINK EX200 has a command execution vulnerability, which can be exploited by an attacker to gain control of the server.
| VAR-202112-0112 | CVE-2021-43471 | Canon LBP223 Weak password requirement vulnerability in printers |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
In Canon LBP223 printers, the System Manager Mode login does not require an account password or PIN. An attacker can remotely shut down the device after entering the background, creating a denial of service vulnerability. Canon LBP223 A weak password requirement vulnerability exists in the printer.Service operation interruption (DoS) It may be in a state. Canon LBP223 is a printer of Canon (Canon) in Japan
| VAR-202112-0049 | CVE-2021-24938 | WordPress for WOOCS Cross-site scripting vulnerability in plugins |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
The WOOCS WordPress plugin before 1.3.7.1 does not sanitise and escape the key parameter of the woocs_update_profiles_data AJAX action (available to any authenticated user) before outputting it back in the response, leading to a Reflected cross-Site Scripting issue. WordPress for WOOCS A cross-site scripting vulnerability exists in the plugin.Information may be obtained and information may be tampered with
| VAR-202112-0911 | CVE-2021-30273 | plural Snapdragon Product Reachable Assertion Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Possible assertion due to improper handling of IPV6 packet with invalid length in destination options header in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Wearables. plural Snapdragon A reachable assertion vulnerability exists in the product.Service operation interruption (DoS) It may be in a state
| VAR-202112-0910 | CVE-2021-30272 | plural Qualcomm In the product NULL Pointer dereference vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible null pointer dereference in thread cache operation handler due to lack of validation of user provided input in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product has NULL There is a vulnerability in pointer dereference.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0909 | CVE-2021-30271 | plural Qualcomm In the product NULL Pointer dereference vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible null pointer dereference in trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product has NULL There is a vulnerability in pointer dereference.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0908 | CVE-2021-30270 | plural Qualcomm In the product NULL Pointer dereference vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible null pointer dereference in thread profile trap handler due to lack of thread ID validation before dereferencing it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product has NULL There is a vulnerability in pointer dereference.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0906 | CVE-2021-30268 | plural Qualcomm Classic buffer overflow vulnerability in the product |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible heap Memory Corruption Issue due to lack of input validation when sending HWTC IQ Capture command in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-1035 | CVE-2021-30289 | plural Qualcomm Product Exceptional State Handling Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible buffer overflow due to lack of range check while processing a DIAG command for COEX management in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. plural Qualcomm The product contains an exceptional state handling vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0916 | CVE-2021-30303 | plural Qualcomm Classic buffer overflow vulnerability in the product |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible buffer overflow due to lack of buffer length check when segmented WMI command is received in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0901 | CVE-2021-30351 | plural Qualcomm Classic buffer overflow vulnerability in the product |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
An out of bound memory access can occur due to improper validation of number of frames being passed during music playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a classic buffer overflow vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-0900 | CVE-2021-30293 | plural Qualcomm Product Reachable Assertion Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Possible assertion due to lack of input validation in PUSCH configuration in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT. plural Qualcomm A reachable assertion vulnerability exists in the product.Service operation interruption (DoS) It may be in a state
| VAR-202112-0896 | CVE-2021-30337 | plural Qualcomm Product Use of Freed Memory Vulnerability |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. plural Qualcomm The product contains a usage of freed memory vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202112-1033 | CVE-2021-30348 | plural Qualcomm Product resource exhaustion vulnerability |
CVSS V2: 3.3 CVSS V3: 6.5 Severity: MEDIUM |
Improper validation of LLM utility timers availability can lead to denial of service in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music. plural Qualcomm The product contains a resource exhaustion vulnerability.Service operation interruption (DoS) It may be in a state