Записи airdroid
8 опубликованных записей вендора airdroid.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-287 Improper Authentication2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-310 Cryptographic Issues1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
34Наблюдать | CVE-2019-9599Proof of concept | The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultaneairdroid · airdroid | Высокая7,5 | — | 13,3 % | 6 мар. 2019 г. |
30Наблюдать | CVE-2012-3885Эксплойта нет | The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to airdroid · airdroid · CWE-287 | Высокая7,5 | — | 1,3 % | 26 июл. 2012 г. |
20Наблюдать | CVE-2012-3888Эксплойта нет | The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass airdroid · airdroid · CWE-264 | Средняя5,0 | — | 1,4 % | 26 июл. 2012 г. |
20Наблюдать | CVE-2012-3884Эксплойта нет | AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote attairdroid · airdroid · CWE-287 | Средняя5,0 | — | 1,4 % | 26 июл. 2012 г. |
20Наблюдать | CVE-2012-3887Эксплойта нет | AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, whichairdroid · airdroid · CWE-310 | Средняя5,0 | — | 1,3 % | 26 июл. 2012 г. |
20Наблюдать | CVE-2012-3886Эксплойта нет | AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attacairdroid · airdroid · CWE-200 | Средняя5,0 | — | 1,3 % | 26 июл. 2012 г. |
17Наблюдать | CVE-2013-0134Эксплойта нет | Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML viaairdroid · airdroid · CWE-79 | Средняя4,3 | — | 1,0 % | 8 апр. 2013 г. |
17Наблюдать | CVE-2015-5661Эксплойта нет | The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive iairdroid · airdroid · CWE-200 | Средняя4,3 | — | 0,9 % | 18 окт. 2015 г. |
- CVE-2019-959934Наблюдать
The AirDroid application through 4.2.1.6 for Android allows remote attackers to cause a denial of service (service crash) via many simultane
ВысокаяCVSS 7,5Proof of conceptEPSS 13 %airdroid · airdroid6 мар. 2019 г.
- CVE-2012-388530Наблюдать
The default configuration of AirDroid 1.0.4 beta uses a four-character alphanumeric password, which makes it easier for remote attackers to
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %airdroid · airdroid26 июл. 2012 г.
- CVE-2012-388820Наблюдать
The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass
СредняяCVSS 5,0Эксплойта нетEPSS 1 %airdroid · airdroid26 июл. 2012 г.
- CVE-2012-388420Наблюдать
AirDroid 1.0.4 beta implements authentication through direct transmission of a password hash over HTTP, which makes it easier for remote att
СредняяCVSS 5,0Эксплойта нетEPSS 1 %airdroid · airdroid26 июл. 2012 г.
- CVE-2012-388720Наблюдать
AirDroid before 1.0.7 beta uses a cleartext base64 format for data transfer that is documented as an "Encrypted Transmission" feature, which
СредняяCVSS 5,0Эксплойта нетEPSS 1 %airdroid · airdroid26 июл. 2012 г.
- CVE-2012-388620Наблюдать
AirDroid 1.0.4 beta uses the MD5 algorithm for values in the checklogin key parameter and 7bb cookie, which makes it easier for remote attac
СредняяCVSS 5,0Эксплойта нетEPSS 1 %airdroid · airdroid26 июл. 2012 г.
- CVE-2013-013417Наблюдать
Cross-site scripting (XSS) vulnerability in the web interface in AirDroid allows remote attackers to inject arbitrary web script or HTML via
СредняяCVSS 4,3Эксплойта нетEPSS 1 %airdroid · airdroid8 апр. 2013 г.
- CVE-2015-566117Наблюдать
The SAND STUDIO AirDroid application 1.1.0 and earlier for Android mishandles implicit intents, which allows attackers to obtain sensitive i
СредняяCVSS 4,3Эксплойта нетEPSS 1 %airdroid · airdroid18 окт. 2015 г.