Записи Logitech
37 опубликованных записей вендора logitech.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 2,7 %
- Pre-auth RCE
- 5
- С записью об исправлении
- 2,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-426 Untrusted Search Path2
- CWE-306 Missing Authentication for Critical Function1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
42В плане | CVE-2012-1250Эксплойта нет | Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminislogitech · lan-w300n\/ru2 firmware · CWE-264 | Критическая10,0 | — | 5,9 % | 4 июн. 2012 г. |
40В плане | CVE-2008-0956Эксплойта нет | Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInbackweb · backweb · CWE-119 | Критическая9,3 | — | 8,4 % | 11 июн. 2008 г. |
40В плане | CVE-2018-15723Эксплойта нет | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Критическая9,8 | — | 3,7 % | 20 дек. 2018 г. |
40В плане | CVE-2018-15721Эксплойта нет | The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.logitech · harmony hub firmware · CWE-287 | Критическая9,8 | — | 1,8 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2018-15720Эксплойта нет | Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the locallogitech · harmony hub firmware · CWE-798 | Критическая9,8 | — | 1,5 % | 20 дек. 2018 г. |
39Наблюдать | CVE-2024-2537Эксплойта нет | Electron Code Injection in Logi Tune macOS Applicationlogitech · logi tune · CWE-913 | Критическая9,8 | — | 0,3 % | 15 мар. 2024 г. |
37Наблюдать | CVE-2007-2918Готовый эксплойт | Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Starlogitech · videocall | Средняя6,8 | — | 34,1 % | 31 мая 2007 г. |
35Наблюдать | CVE-2019-12506Эксплойта нет | Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone tlogitech · r700 laser presentation remote firmware · CWE-306 | Высокая8,8 | — | 1,3 % | 7 июн. 2019 г. |
35Наблюдать | CVE-2022-0916Эксплойта нет | Broken authentication on Logitech Options due to misvalidation of Oauth state parameterlogitech · options · CWE-287 | Высокая8,8 | — | 0,5 % | 3 мая 2022 г. |
32Наблюдать | CVE-2018-15722Эксплойта нет | The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.logitech · harmony hub firmware · CWE-78 | Высокая8,1 | — | 1,6 % | 20 дек. 2018 г. |
31Наблюдать | CVE-2001-0737Эксплойта нет | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middlelogitech · cordless freedom | Высокая7,5 | — | 1,7 % | 18 окт. 2001 г. |
31Наблюдать | CVE-2018-0620Эксплойта нет | Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan hologitech · game software · CWE-426 | Высокая7,8 | — | 0,9 % | 26 июл. 2018 г. |
31Наблюдать | CVE-2018-0621Эксплойта нет | Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges vialogitech · connection utility software · CWE-426 | Высокая7,8 | — | 0,9 % | 26 июл. 2018 г. |
29Наблюдать | CVE-2022-36263Эксплойта нет | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.logitech · streamlabs desktop · CWE-284 | Высокая7,3 | — | 0,4 % | 19 авг. 2022 г. |
28Наблюдать | CVE-2022-0915Эксплойта нет | Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalationlogitech · sync · CWE-367 | Высокая7,0 | — | 0,2 % | 12 апр. 2022 г. |
27Наблюдать | CVE-2021-20640Эксплойта нет | Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command logitech · lan-w300n\/pgrb firmware · CWE-120 | Средняя6,8 | — | 0,6 % | 12 февр. 2021 г. |
27Наблюдать | CVE-2021-20638Эксплойта нет | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Средняя6,8 | — | 0,5 % | 12 февр. 2021 г. |
27Наблюдать | CVE-2021-20639Эксплойта нет | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Средняя6,8 | — | 0,5 % | 12 февр. 2021 г. |
26Наблюдать | CVE-2019-13055Эксплойта нет | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freqlogitech · unifying receiver firmware · CWE-200 | Средняя6,5 | — | 1,0 % | 29 июн. 2019 г. |
26Наблюдать | CVE-2021-20642Эксплойта нет | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) conlogitech · lan-w300n\/rs firmware | Средняя6,5 | — | 1,0 % | 12 февр. 2021 г. |
26Наблюдать | CVE-2021-20637Эксплойта нет | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) clogitech · lan-w300n\/pr5b firmware | Средняя6,5 | — | 1,0 % | 12 февр. 2021 г. |
26Наблюдать | CVE-2016-6257Эксплойта нет | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60lenovo · ultraslim firmware · CWE-310 | Средняя6,5 | — | 1,0 % | 2 авг. 2016 г. |
26Наблюдать | CVE-2019-13054Эксплойта нет | The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.logitech · r500 firmware · CWE-522 | Средняя6,5 | — | 0,8 % | 29 июн. 2019 г. |
26Наблюдать | CVE-2016-10761Эксплойта нет | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.logitech · k400r firmware · CWE-74 | Средняя6,5 | — | 0,7 % | 29 июн. 2019 г. |
26Наблюдать | CVE-2019-13052Эксплойта нет | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.logitech · unifying receiver firmware · CWE-327 | Средняя6,5 | — | 0,7 % | 29 июн. 2019 г. |
- CVE-2012-125042В плане
Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminis
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %logitech · lan-w300n\/ru2 firmware4 июн. 2012 г.
- CVE-2008-095640В плане
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteIn
КритическаяCVSS 9,3Эксплойта нетEPSS 8 %backweb · backweb11 июн. 2008 г.
- CVE-2018-1572340В плане
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %logitech · harmony hub firmware20 дек. 2018 г.
- CVE-2018-1572140В плане
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %logitech · harmony hub firmware20 дек. 2018 г.
- CVE-2018-1572039Наблюдать
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %logitech · harmony hub firmware20 дек. 2018 г.
- CVE-2024-253739Наблюдать
Electron Code Injection in Logi Tune macOS Application
КритическаяCVSS 9,8Эксплойта нетEPSS 0 %logitech · logi tune15 мар. 2024 г.
- CVE-2007-291837Наблюдать
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Star
СредняяCVSS 6,8Готовый эксплойтEPSS 34 %logitech · videocall31 мая 2007 г.
- CVE-2019-1250635Наблюдать
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone t
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %logitech · r700 laser presentation remote firmware7 июн. 2019 г.
- CVE-2022-091635Наблюдать
Broken authentication on Logitech Options due to misvalidation of Oauth state parameter
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %logitech · options3 мая 2022 г.
- CVE-2018-1572232Наблюдать
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.
ВысокаяCVSS 8,1Эксплойта нетEPSS 2 %logitech · harmony hub firmware20 дек. 2018 г.
- CVE-2001-073731Наблюдать
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %logitech · cordless freedom18 окт. 2001 г.
- CVE-2018-062031Наблюдать
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan ho
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %logitech · game software26 июл. 2018 г.
- CVE-2018-062131Наблюдать
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %logitech · connection utility software26 июл. 2018 г.
- CVE-2022-3626329Наблюдать
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %logitech · streamlabs desktop19 авг. 2022 г.
- CVE-2022-091528Наблюдать
Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %logitech · sync12 апр. 2022 г.
- CVE-2021-2064027Наблюдать
Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command
СредняяCVSS 6,8Эксплойта нетEPSS 1 %logitech · lan-w300n\/pgrb firmware12 февр. 2021 г.
- CVE-2021-2063827Наблюдать
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %logitech · lan-w300n\/pgrb firmware12 февр. 2021 г.
- CVE-2021-2063927Наблюдать
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
СредняяCVSS 6,8Эксплойта нетEPSS 0 %logitech · lan-w300n\/pgrb firmware12 февр. 2021 г.
- CVE-2019-1305526Наблюдать
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freq
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · unifying receiver firmware29 июн. 2019 г.
- CVE-2021-2064226Наблюдать
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) con
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · lan-w300n\/rs firmware12 февр. 2021 г.
- CVE-2021-2063726Наблюдать
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) c
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · lan-w300n\/pr5b firmware12 февр. 2021 г.
- CVE-2016-625726Наблюдать
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60
СредняяCVSS 6,5Эксплойта нетEPSS 1 %lenovo · ultraslim firmware2 авг. 2016 г.
- CVE-2019-1305426Наблюдать
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · r500 firmware29 июн. 2019 г.
- CVE-2016-1076126Наблюдать
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · k400r firmware29 июн. 2019 г.
- CVE-2019-1305226Наблюдать
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
СредняяCVSS 6,5Эксплойта нетEPSS 1 %logitech · unifying receiver firmware29 июн. 2019 г.