Sony records
75 published records for vendor sony.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 14
- With a fix record
- 1.3%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-426 Untrusted Search Path6
- CWE-427 Uncontrolled Search Path Element5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-306 Missing Authentication for Critical Function3
- CWE-352 Cross-Site Request Forgery (CSRF)2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
75 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
45Plan | CVE-2007-3488Proof of concept | Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CSsony · sony network camera snc-p5 | Critical10.0 | — | 16.2% | Jun 29, 2007 |
45Plan | CVE-2008-0748Proof of concept | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 sony · axruploadserver activex control · CWE-119 | Critical10.0 | — | 16.2% | Feb 13, 2008 |
42Plan | CVE-2022-23747No exploit | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed sony · xperia 1 firmware · CWE-120 | Critical9.8 | — | 10.2% | Aug 17, 2022 |
42Plan | CVE-2006-4289No exploit | Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspesony · vaio media server | Critical10.0 | — | 6.1% | Aug 22, 2006 |
41Plan | CVE-2012-0985Proof of concept | Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wirelsony · smartwi connection utillity · CWE-119 | Critical9.3 | — | 13.0% | Jun 7, 2012 |
41Plan | CVE-2018-3938No exploit | An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5sony · snc-eb600 firmware · CWE-787 | Critical10.0 | — | 3.3% | Aug 14, 2018 |
40Plan | CVE-2007-5709Proof of concept | Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file namsony · sonicstage connect player · CWE-119 | Critical9.3 | — | 10.9% | Oct 30, 2007 |
39Monitor | CVE-2019-10844No exploit | nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which sony · neural network libraries | Critical9.8 | — | 1.6% | Apr 4, 2019 |
37Monitor | CVE-2020-36885No exploit | Sony IPELA Network Camera 1.82.01 Remote Stack Buffer Overflow via ftpclient.cgisony · snc-dh120t firmware · CWE-787 | Critical9.3 | — | 1.2% | Dec 10, 2025 |
36Monitor | CVE-2016-7834Proof of concept | SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, Ssony · snc series firmware · CWE-200 | High8.8 | — | 3.9% | Apr 13, 2017 |
36Monitor | CVE-2017-2277No exploit | WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage cosony · wg-c10 firmware | Critical9.1 | — | 1.1% | Jul 21, 2017 |
35Monitor | CVE-2024-23934No exploit | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilitysony · xav-ax5500 · CWE-121 | High8.8 | — | 1.0% | Sep 23, 2024 |
35Monitor | CVE-2018-16593No exploit | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.sony · r5c firmware · CWE-78 | High8.8 | — | 0.9% | Jun 19, 2019 |
35Monitor | CVE-2016-7830No exploit | Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices sony · pcs-xg100 firmware · CWE-306 | High8.8 | — | 0.7% | Jun 9, 2017 |
35Monitor | CVE-2020-5589No exploit | SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPsony · wf-1000x firmware · CWE-306 | High8.8 | — | 0.6% | Jun 9, 2020 |
35Monitor | CVE-2025-5478No exploit | Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerabilitysony · xav-ax8500 firmware · CWE-190 | High8.8 | — | 0.4% | Jun 20, 2025 |
35Monitor | CVE-2025-5476No exploit | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-653 | High8.8 | — | 0.4% | Jun 20, 2025 |
35Monitor | CVE-2025-5820No exploit | Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-288 | High8.8 | — | 0.4% | Jun 20, 2025 |
34Monitor | CVE-2012-2210Proof of concept | The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCsony · bravia tv · CWE-399 | High7.8 | — | 9.1% | Apr 11, 2012 |
33Monitor | CVE-2019-11336No exploit | Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) bysony · photo sharing plus · CWE-532 | High8.1 | — | 3.2% | May 14, 2019 |
32Monitor | CVE-2017-10909No exploit | Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan horsony · music center · CWE-426 | High7.8 | — | 1.9% | Dec 22, 2017 |
32Monitor | CVE-2018-16594No exploit | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.sony · r5c firmware · CWE-22 | High8.1 | — | 0.9% | Jun 19, 2019 |
31Monitor | CVE-2018-3937No exploit | An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 fsony · snc-eb600 firmware · CWE-78 | High7.2 | — | 9.6% | Aug 14, 2018 |
31Monitor | CVE-2006-4235No exploit | Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to exesony · sonicstage mastering studio | High7.5 | — | 5.0% | Aug 21, 2006 |
31Monitor | CVE-2019-11890No exploit | Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wiredsony · bravia firmware · CWE-400 | High7.5 | — | 4.4% | Jul 9, 2019 |
- CVE-2007-348845Plan
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS
CriticalCVSS 10.0Proof of conceptEPSS 16%sony · sony network camera snc-p5Jun 29, 2007
- CVE-2008-074845Plan
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38
CriticalCVSS 10.0Proof of conceptEPSS 16%sony · axruploadserver activex controlFeb 13, 2008
- CVE-2022-2374742Plan
In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed
CriticalCVSS 9.8No exploitEPSS 10%sony · xperia 1 firmwareAug 17, 2022
- CVE-2006-428942Plan
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspe
CriticalCVSS 10.0No exploitEPSS 6%sony · vaio media serverAug 22, 2006
- CVE-2012-098541Plan
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wirel
CriticalCVSS 9.3Proof of conceptEPSS 13%sony · smartwi connection utillityJun 7, 2012
- CVE-2018-393841Plan
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5
CriticalCVSS 10.0No exploitEPSS 3%sony · snc-eb600 firmwareAug 14, 2018
- CVE-2007-570940Plan
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file nam
CriticalCVSS 9.3Proof of conceptEPSS 11%sony · sonicstage connect playerOct 30, 2007
- CVE-2019-1084439Monitor
nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which
CriticalCVSS 9.8No exploitEPSS 2%sony · neural network librariesApr 4, 2019
- CVE-2020-3688537Monitor
Sony IPELA Network Camera 1.82.01 Remote Stack Buffer Overflow via ftpclient.cgi
CriticalCVSS 9.3No exploitEPSS 1%sony · snc-dh120t firmwareDec 10, 2025
- CVE-2016-783436Monitor
SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, S
HighCVSS 8.8Proof of conceptEPSS 4%sony · snc series firmwareApr 13, 2017
- CVE-2017-227736Monitor
WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage co
CriticalCVSS 9.1No exploitEPSS 1%sony · wg-c10 firmwareJul 21, 2017
- CVE-2024-2393435Monitor
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 1%sony · xav-ax5500Sep 23, 2024
- CVE-2018-1659335Monitor
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
HighCVSS 8.8No exploitEPSS 1%sony · r5c firmwareJun 19, 2019
- CVE-2016-783035Monitor
Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices
HighCVSS 8.8No exploitEPSS 1%sony · pcs-xg100 firmwareJun 9, 2017
- CVE-2020-558935Monitor
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP
HighCVSS 8.8No exploitEPSS 1%sony · wf-1000x firmwareJun 9, 2020
- CVE-2025-547835Monitor
Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability
HighCVSS 8.8No exploitEPSS 0%sony · xav-ax8500 firmwareJun 20, 2025
- CVE-2025-547635Monitor
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
HighCVSS 8.8No exploitEPSS 0%sony · xav-ax8500 firmwareJun 20, 2025
- CVE-2025-582035Monitor
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability
HighCVSS 8.8No exploitEPSS 0%sony · xav-ax8500 firmwareJun 20, 2025
- CVE-2012-221034Monitor
The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TC
HighCVSS 7.8Proof of conceptEPSS 9%sony · bravia tvApr 11, 2012
- CVE-2019-1133633Monitor
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by
HighCVSS 8.1No exploitEPSS 3%sony · photo sharing plusMay 14, 2019
- CVE-2017-1090932Monitor
Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan hor
HighCVSS 7.8No exploitEPSS 2%sony · music centerDec 22, 2017
- CVE-2018-1659432Monitor
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
HighCVSS 8.1No exploitEPSS 1%sony · r5c firmwareJun 19, 2019
- CVE-2018-393731Monitor
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 f
HighCVSS 7.2No exploitEPSS 10%sony · snc-eb600 firmwareAug 14, 2018
- CVE-2006-423531Monitor
Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to exe
HighCVSS 7.5No exploitEPSS 5%sony · sonicstage mastering studioAug 21, 2006
- CVE-2019-1189031Monitor
Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired
HighCVSS 7.5No exploitEPSS 4%sony · bravia firmwareJul 9, 2019