Thomson records
9 published records for vendor thomson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2006-0947Proof of concept | Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in thethomson · speedtouch | High7.5 | — | 2.7% | Feb 28, 2006 |
31Monitor | CVE-2004-0641Proof of concept | Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numbthomson · speedtouch | High7.5 | — | 2.6% | Aug 5, 2004 |
31Monitor | CVE-2005-0494Proof of concept | The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly valthomson · thomson cable modem | High7.5 | — | 2.6% | Feb 21, 2005 |
28Monitor | CVE-2014-4716Proof of concept | Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified victhomson · twg87ouir · CWE-352 | Medium6.8 | — | 2.3% | Jul 3, 2014 |
22Monitor | CVE-2007-4553Proof of concept | The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message thomson · st 2030 sip phone | Medium5.0 | — | 8.2% | Aug 27, 2007 |
21Monitor | CVE-2003-1085Proof of concept | The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unstathomson · tcm cable modem | Medium5.0 | — | 4.9% | Dec 31, 2003 |
21Monitor | CVE-2007-4753No exploit | The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP mthomson · st 2030 sip phone | Medium5.0 | — | 1.7% | Sep 7, 2007 |
18Monitor | CVE-2006-0946Proof of concept | Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrarythomson · speedtouch | Medium4.3 | — | 2.0% | Feb 28, 2006 |
17Monitor | CVE-2007-6003Proof of concept | Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers tothomson · speedtouch · CWE-79 | Medium4.3 | — | 1.2% | Nov 15, 2007 |
- CVE-2006-094731Monitor
Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the
HighCVSS 7.5Proof of conceptEPSS 3%thomson · speedtouchFeb 28, 2006
- CVE-2004-064131Monitor
Thomson SpeedTouch 510 ADSL Router with firmware GV8BAA3.270, and possibly earlier versions, generates predictable TCP Initial Sequence Numb
HighCVSS 7.5Proof of conceptEPSS 3%thomson · speedtouchAug 5, 2004
- CVE-2005-049431Monitor
The RgSecurity form in the HTTP server for the Thomson TCW690 cable modem running firmware 2.1 and software ST42.03.0a does not properly val
HighCVSS 7.5Proof of conceptEPSS 3%thomson · thomson cable modemFeb 21, 2005
- CVE-2014-471628Monitor
Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authentication of unspecified vic
MediumCVSS 6.8Proof of conceptEPSS 2%thomson · twg87ouirJul 3, 2014
- CVE-2007-455322Monitor
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via an INVITE message
MediumCVSS 5.0Proof of conceptEPSS 8%thomson · st 2030 sip phoneAug 27, 2007
- CVE-2003-108521Monitor
The HTTP server in the Thomson TWC305, TWC315, and TCW690 cable modem ST42.03.0a allows remote attackers to cause a denial of service (unsta
MediumCVSS 5.0Proof of conceptEPSS 5%thomson · tcm cable modemDec 31, 2003
- CVE-2007-475321Monitor
The Thomson ST 2030 SIP phone with software 1.52.1 allows remote attackers to cause a denial of service (device hang) via (1) an empty SIP m
MediumCVSS 5.0No exploitEPSS 2%thomson · st 2030 sip phoneSep 7, 2007
- CVE-2006-094618Monitor
Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary
MediumCVSS 4.3Proof of conceptEPSS 2%thomson · speedtouchFeb 28, 2006
- CVE-2007-600317Monitor
Cross-site scripting (XSS) vulnerability in cgi/b/ic/connect in the Thomson SpeedTouch 716 with firmware 5.4.0.14 allows remote attackers to
MediumCVSS 4.3Proof of conceptEPSS 1%thomson · speedtouchNov 15, 2007