HTC records
16 published records for vendor htc.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-255 Credentials Management Errors3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-264 Permissions, Privileges, and Access Controls1
- CWE-269 Improper Privilege Management1
- CWE-295 Improper Certificate Validation1
- CWE-427 Uncontrolled Search Path Element1
The weakness classes this vendor ships most often: where to look.
CWEAll records
16 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2024-33267No exploit | SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayBCWE-89 | Critical9.8 | — | 0.5% | Apr 30, 2024 |
35Monitor | CVE-2018-1170No exploit | This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen volkswagen · customer-link · CWE-693 | High8.8 | — | 0.8% | Mar 1, 2018 |
32Monitor | CVE-2007-3362No exploit | ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of htc · hytn | High7.8 | — | 2.0% | Jun 22, 2007 |
31Monitor | CVE-2019-12177No exploit | Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local atthtc · viveport · CWE-427 | High7.8 | — | 1.4% | Jun 3, 2019 |
31Monitor | CVE-2019-12176No exploit | Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to eschtc · viveport · CWE-269 | High7.8 | — | 0.3% | Jun 3, 2019 |
30Monitor | CVE-2008-4295Proof of concept | Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth comicrosoft · windows mobile · CWE-20 | Medium5.4 | — | 30.1% | Sep 27, 2008 |
30Monitor | CVE-2013-4622No exploit | The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote htc · droid incredible · CWE-255 | High7.5 | — | 1.3% | Jun 19, 2013 |
29Monitor | CVE-2008-6775Proof of concept | HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectivhtc · touch cruise | High7.1 | — | 2.5% | May 1, 2009 |
29Monitor | CVE-2012-2980No exploit | The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Chahtc · chacha · CWE-255 | High7.1 | — | 1.8% | Aug 21, 2012 |
26Monitor | CVE-2012-2217No exploit | The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D behtc · evo 4g software · CWE-264 | Medium6.4 | — | 2.0% | May 1, 2012 |
23Monitor | CVE-2013-10001No exploit | HTC One/Sense Mail Client certificate validationhtc · mail · CWE-295 | Medium5.9 | — | 0.6% | May 17, 2022 |
20Monitor | CVE-2010-1730No exploit | Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <mdolphin · dolphin browser · CWE-119 | Medium5.0 | — | 1.2% | May 6, 2010 |
17Monitor | CVE-2010-1731No exploit | Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> google · chrome | Medium4.3 | — | 0.8% | May 6, 2010 |
10Monitor | CVE-2011-4872No exploit | Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Zhtc · desire hd · CWE-200 | Low2.6 | — | 1.3% | Feb 5, 2012 |
10Monitor | CVE-2011-3975No exploit | A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecifiedhtc · evo 3d · CWE-200 | Low2.6 | — | 1.0% | Oct 3, 2011 |
9Monitor | CVE-2008-4540No exploit | Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, whichhtc · hermes · CWE-255 | Low2.1 | — | 2.0% | Oct 13, 2008 |
- CVE-2024-3326739Monitor
SQL Injection vulnerability in Hero hfheropayment v.1.2.5 and before allows an attacker to escalate privileges via the HfHeropaymentGatewayB
CriticalCVSS 9.8No exploitEPSS 1%Apr 30, 2024
- CVE-2018-117035Monitor
This vulnerability allows adjacent attackers to inject arbitrary Controller Area Network messages on vulnerable installations of Volkswagen
HighCVSS 8.8No exploitEPSS 1%volkswagen · customer-linkMar 1, 2018
- CVE-2007-336232Monitor
ageet AGEphone before 1.6.2, running on Windows Mobile 5 on the HTC HyTN Pocket PC device, allows remote attackers to (1) cause a denial of
HighCVSS 7.8No exploitEPSS 2%htc · hytnJun 22, 2007
- CVE-2019-1217731Monitor
Privilege escalation due to insecure directory permissions affecting ViveportDesktopService in HTC VIVEPORT before 1.0.0.36 allows local att
HighCVSS 7.8No exploitEPSS 1%htc · viveportJun 3, 2019
- CVE-2019-1217631Monitor
Privilege escalation in the "HTC Account Service" and "ViveportDesktopService" in HTC VIVEPORT before 1.0.0.36 allows local attackers to esc
HighCVSS 7.8No exploitEPSS 0%htc · viveportJun 3, 2019
- CVE-2008-429530Monitor
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth co
MediumCVSS 5.4Proof of conceptEPSS 30%microsoft · windows mobileSep 27, 2008
- CVE-2013-462230Monitor
The 3G Mobile Hotspot feature on the HTC Droid Incredible has a default WPA2 PSK passphrase of 1234567890, which makes it easier for remote
HighCVSS 7.5No exploitEPSS 1%htc · droid incredibleJun 19, 2013
- CVE-2008-677529Monitor
HTC Touch Pro and HTC Touch Cruise vCard allows remote attackers to cause denial of service (CPU consumption, SMS consumption, and connectiv
HighCVSS 7.1Proof of conceptEPSS 3%htc · touch cruiseMay 1, 2009
- CVE-2012-298029Monitor
The Samsung and HTC onTouchEvent method implementation for Android on the T-Mobile myTouch 3G Slide, HTC Merge, Sprint EVO Shift 4G, HTC Cha
HighCVSS 7.1No exploitEPSS 2%htc · chachaAug 21, 2012
- CVE-2012-221726Monitor
The HTC IQRD service for Android on the HTC EVO 4G before 4.67.651.3, EVO Design 4G before 2.12.651.5, Shift 4G before 2.77.651.3, EVO 3D be
MediumCVSS 6.4No exploitEPSS 2%htc · evo 4g softwareMay 1, 2012
- CVE-2013-1000123Monitor
HTC One/Sense Mail Client certificate validation
MediumCVSS 5.9No exploitEPSS 1%htc · mailMay 17, 2022
- CVE-2010-173020Monitor
Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <m
MediumCVSS 5.0No exploitEPSS 1%dolphin · dolphin browserMay 6, 2010
- CVE-2010-173117Monitor
Google Chrome on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee>
MediumCVSS 4.3No exploitEPSS 1%google · chromeMay 6, 2010
- CVE-2011-487210Monitor
Multiple HTC Android devices including Desire HD FRG83D and GRI40, Glacier FRG83, Droid Incredible FRF91, Thunderbolt 4G FRG83D, Sensation Z
LowCVSS 2.6No exploitEPSS 1%htc · desire hdFeb 5, 2012
- CVE-2011-397510Monitor
A certain HTC update for Android 2.3.4 build GRJ22, when the Sense interface is used on the HTC EVO 3D, EVO 4G, ThunderBolt, and unspecified
LowCVSS 2.6No exploitEPSS 1%htc · evo 3dOct 3, 2011
- CVE-2008-45409Monitor
Windows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which
LowCVSS 2.1No exploitEPSS 2%htc · hermesOct 13, 2008