Записи Philips
115 опубликованных записей вендора philips.
Профиль для исследователя
- Попали в KEV
- 2 · 1,7 %
- С эксплойтом
- 2 · 1,7 %
- Pre-auth RCE
- 16
- С записью об исправлении
- 1,7 %
- Медиана: публикация → KEV
- 1680 дн.
Повторяющиеся классы
- CWE-798 Use of Hard-coded Credentials6
- CWE-122 Heap-based Buffer Overflow6
- CWE-20 Improper Input Validation6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-287 Improper Authentication4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
115 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
93Срочно | CVE-2017-0143Готовый эксплойт | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold anmicrosoft · server message block | Высокая8,8 | KEV | 93,3 % | 16 мар. 2017 г. |
91Срочно | CVE-2017-0199Готовый эксплойт | Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windowsmicrosoft · office | Высокая7,8 | KEV | 99,5 % | 12 апр. 2017 г. |
41В плане | CVE-2018-5474Эксплойта нет | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to executphilips · intellispace portal · CWE-20 | Критическая9,8 | — | 6,1 % | 26 мар. 2018 г. |
40В плане | CVE-2018-5472Эксплойта нет | Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to philips · intellispace portal · CWE-264 | Критическая9,8 | — | 4,5 % | 26 мар. 2018 г. |
40В плане | CVE-2018-5468Эксплойта нет | Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain unaphilips · intellispace portal · CWE-264 | Критическая9,8 | — | 4,5 % | 26 мар. 2018 г. |
40В плане | CVE-2018-8850Эксплойта нет | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-20 | Критическая9,8 | — | 3,8 % | 26 сент. 2018 г. |
40В плане | CVE-2018-5451Эксплойта нет | In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficienphilips · alice 6 firmware · CWE-287 | Критическая9,8 | — | 2,6 % | 28 мар. 2018 г. |
39Наблюдать | CVE-2015-2882Эксплойта нет | Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a pphilips · in.sight b120\\37 · CWE-798 | Критическая9,8 | — | 1,6 % | 9 апр. 2017 г. |
39Наблюдать | CVE-2018-8856Эксплойта нет | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-798 | Критическая9,8 | — | 1,4 % | 26 сент. 2018 г. |
39Наблюдать | CVE-2021-27501Эксплойта нет | Philips Vue PACS Improper Adherence to Coding Standardsphilips · myvue · CWE-710 | Критическая9,8 | — | 0,9 % | 1 апр. 2022 г. |
39Наблюдать | CVE-2021-27497Эксплойта нет | Philips Vue PACS Protection Mechanism Failurephilips · myvue · CWE-693 | Критическая9,8 | — | 0,8 % | 1 апр. 2022 г. |
39Наблюдать | CVE-2018-7498Эксплойта нет | In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrityphilips · alice 6 firmware · CWE-311 | Критическая9,8 | — | 0,6 % | 28 мар. 2018 г. |
38Наблюдать | CVE-2013-2808Эксплойта нет | Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vasculaphilips · xper information management physiomonitoring 5 · CWE-119 | Критическая9,3 | — | 4,3 % | 5 окт. 2013 г. |
37Наблюдать | CVE-2017-9656Эксплойта нет | The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a databasephilips · dosewise · CWE-798 | Критическая9,1 | — | 2,3 % | 24 апр. 2018 г. |
36Наблюдать | CVE-2018-8852Эксплойта нет | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-384 | Высокая8,8 | — | 1,9 % | 26 сент. 2018 г. |
35Наблюдать | CVE-2021-39376Эксплойта нет | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSISphilips · tasy electronic medical record · CWE-89 | Высокая8,8 | — | 1,3 % | 24 авг. 2021 г. |
35Наблюдать | CVE-2021-39375Эксплойта нет | Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValuphilips · tasy electronic medical record · CWE-89 | Высокая8,8 | — | 1,3 % | 24 авг. 2021 г. |
35Наблюдать | CVE-2017-9654Эксплойта нет | The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend syphilips · dosewise · CWE-312 | Высокая8,8 | — | 1,0 % | 24 апр. 2018 г. |
35Наблюдать | CVE-2018-8844Эксплойта нет | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-352 | Высокая8,8 | — | 0,9 % | 26 сент. 2018 г. |
35Наблюдать | CVE-2018-17906Эксплойта нет | Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.philips · intellispace pacs · CWE-521 | Высокая8,8 | — | 0,8 % | 19 нояб. 2018 г. |
35Наблюдать | CVE-2018-8842Эксплойта нет | Philips e-Alert Unit (non-medical device), Version R2.1 and prior.philips · e-alert firmware · CWE-319 | Высокая8,8 | — | 0,6 % | 26 сент. 2018 г. |
35Наблюдать | CVE-2020-16222Эксплойта нет | Philips Patient Monitoring Devices Improper Authenticationphilips · patient information center ix · CWE-287 | Высокая8,8 | — | 0,5 % | 11 сент. 2020 г. |
35Наблюдать | CVE-2026-3556Эксплойта нет | Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | Высокая8,8 | — | 0,5 % | 16 мар. 2026 г. |
35Наблюдать | CVE-2026-3560Эксплойта нет | Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerabilityphilips · hue bridge v2 firmware · CWE-122 | Высокая8,8 | — | 0,5 % | 16 мар. 2026 г. |
35Наблюдать | CVE-2021-33017Эксплойта нет | Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channelphilips · intellibridge ec40 firmware · CWE-288 | Высокая8,8 | — | 0,5 % | 27 дек. 2021 г. |
- CVE-2017-014393Срочно
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold an
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 93 %microsoft · server message block16 мар. 2017 г.
- CVE-2017-019991Срочно
Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows
ВысокаяCVSS 7,8KEVГотовый эксплойтEPSS 99 %microsoft · office12 апр. 2017 г.
- CVE-2018-547441В плане
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an input validation vulnerability that could allow a remote attacker to execut
КритическаяCVSS 9,8Эксплойта нетEPSS 6 %philips · intellispace portal26 мар. 2018 г.
- CVE-2018-547240В плане
Philips Intellispace Portal all versions 7.0.x and 8.0.x have an insecure windows permissions vulnerability that could allow an attacker to
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %philips · intellispace portal26 мар. 2018 г.
- CVE-2018-546840В плане
Philips Intellispace Portal all versions 7.0.x and 8.0.x have a remote desktop access vulnerability that could allow an attacker to gain una
КритическаяCVSS 9,8Эксплойта нетEPSS 5 %philips · intellispace portal26 мар. 2018 г.
- CVE-2018-885040В плане
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %philips · e-alert firmware26 сент. 2018 г.
- CVE-2018-545140В плане
In Philips Alice 6 System version R8.0.2 or prior, when an actor claims to have a given identity, the software does not prove or insufficien
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %philips · alice 6 firmware28 мар. 2018 г.
- CVE-2015-288239Наблюдать
Philips In.Sight B120/37 has a password of b120root for the backdoor root account, a password of /ADMIN/ for the backdoor admin account, a p
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %philips · in.sight b120\\379 апр. 2017 г.
- CVE-2018-885639Наблюдать
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %philips · e-alert firmware26 сент. 2018 г.
- CVE-2021-2750139Наблюдать
Philips Vue PACS Improper Adherence to Coding Standards
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %philips · myvue1 апр. 2022 г.
- CVE-2021-2749739Наблюдать
Philips Vue PACS Protection Mechanism Failure
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %philips · myvue1 апр. 2022 г.
- CVE-2018-749839Наблюдать
In Philips Alice 6 System version R8.0.2 or prior, the lack of proper data encryption passes up the guarantees of confidentiality, integrity
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %philips · alice 6 firmware28 мар. 2018 г.
- CVE-2013-280838Наблюдать
Heap-based buffer overflow in Xper in Philips Xper Information Management Physiomonitoring 5 components, Xper Information Management Vascula
КритическаяCVSS 9,3Эксплойта нетEPSS 4 %philips · xper information management physiomonitoring 55 окт. 2013 г.
- CVE-2017-965637Наблюдать
The backend database of the Philips DoseWise Portal application versions 1.1.7.333 and 2.1.1.3069 uses hard-coded credentials for a database
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %philips · dosewise24 апр. 2018 г.
- CVE-2018-885236Наблюдать
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %philips · e-alert firmware26 сент. 2018 г.
- CVE-2021-3937635Наблюдать
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the CorCad_F2/executaConsultaEspecifico IE_CORPO_ASSIS
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · tasy electronic medical record24 авг. 2021 г.
- CVE-2021-3937535Наблюдать
Philips Healthcare Tasy Electronic Medical Record (EMR) 3.06 allows SQL injection via the WAdvancedFilter/getDimensionItemsByCode FilterValu
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · tasy electronic medical record24 авг. 2021 г.
- CVE-2017-965435Наблюдать
The Philips DoseWise Portal web-based application versions 1.1.7.333 and 2.1.1.3069 stores login credentials in clear text within backend sy
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · dosewise24 апр. 2018 г.
- CVE-2018-884435Наблюдать
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · e-alert firmware26 сент. 2018 г.
- CVE-2018-1790635Наблюдать
Philips iSite and IntelliSpace PACS, iSite PACS, all versions, and IntelliSpace PACS, all versions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · intellispace pacs19 нояб. 2018 г.
- CVE-2018-884235Наблюдать
Philips e-Alert Unit (non-medical device), Version R2.1 and prior.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · e-alert firmware26 сент. 2018 г.
- CVE-2020-1622235Наблюдать
Philips Patient Monitoring Devices Improper Authentication
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · patient information center ix11 сент. 2020 г.
- CVE-2026-355635Наблюдать
Philips Hue Bridge HomeKit Pair-Setup Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · hue bridge v2 firmware16 мар. 2026 г.
- CVE-2026-356035Наблюдать
Philips Hue Bridge HomeKit hk_hap_pair_storage_put Heap-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %philips · hue bridge v2 firmware16 мар. 2026 г.
- CVE-2021-3301735Наблюдать
Philips IntelliBridge EC 40 and EC 80 Hub Authentication Bypass Using an Alternate Path or Channel
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %philips · intellibridge ec40 firmware27 дек. 2021 г.