Записи Sony
75 опубликованных записей вендора sony.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 14
- С записью об исправлении
- 1,3 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer6
- CWE-426 Untrusted Search Path6
- CWE-427 Uncontrolled Search Path Element5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-306 Missing Authentication for Critical Function3
- CWE-352 Cross-Site Request Forgery (CSRF)2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEОхват bug bounty
Вендор продукта присутствует в публичной программе. Сопоставление по имени; проверьте текст scope в программе.
Все записи
75 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2007-3488Proof of concept | Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CSsony · sony network camera snc-p5 | Критическая10,0 | — | 16,2 % | 29 июн. 2007 г. |
45В плане | CVE-2008-0748Proof of concept | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 sony · axruploadserver activex control · CWE-119 | Критическая10,0 | — | 16,2 % | 13 февр. 2008 г. |
42В плане | CVE-2022-23747Эксплойта нет | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed sony · xperia 1 firmware · CWE-120 | Критическая9,8 | — | 10,2 % | 17 авг. 2022 г. |
42В плане | CVE-2006-4289Эксплойта нет | Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspesony · vaio media server | Критическая10,0 | — | 6,1 % | 22 авг. 2006 г. |
41В плане | CVE-2012-0985Proof of concept | Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wirelsony · smartwi connection utillity · CWE-119 | Критическая9,3 | — | 13,0 % | 7 июн. 2012 г. |
41В плане | CVE-2018-3938Эксплойта нет | An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5sony · snc-eb600 firmware · CWE-787 | Критическая10,0 | — | 3,3 % | 14 авг. 2018 г. |
40В плане | CVE-2007-5709Proof of concept | Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file namsony · sonicstage connect player · CWE-119 | Критическая9,3 | — | 10,9 % | 30 окт. 2007 г. |
39Наблюдать | CVE-2019-10844Эксплойта нет | nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which sony · neural network libraries | Критическая9,8 | — | 1,6 % | 4 апр. 2019 г. |
37Наблюдать | CVE-2020-36885Эксплойта нет | Sony IPELA Network Camera 1.82.01 Remote Stack Buffer Overflow via ftpclient.cgisony · snc-dh120t firmware · CWE-787 | Критическая9,3 | — | 1,2 % | 10 дек. 2025 г. |
36Наблюдать | CVE-2016-7834Proof of concept | SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, Ssony · snc series firmware · CWE-200 | Высокая8,8 | — | 3,9 % | 13 апр. 2017 г. |
36Наблюдать | CVE-2017-2277Эксплойта нет | WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage cosony · wg-c10 firmware | Критическая9,1 | — | 1,1 % | 21 июл. 2017 г. |
35Наблюдать | CVE-2024-23934Эксплойта нет | Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerabilitysony · xav-ax5500 · CWE-121 | Высокая8,8 | — | 1,0 % | 23 сент. 2024 г. |
35Наблюдать | CVE-2018-16593Эксплойта нет | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.sony · r5c firmware · CWE-78 | Высокая8,8 | — | 0,9 % | 19 июн. 2019 г. |
35Наблюдать | CVE-2016-7830Эксплойта нет | Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices sony · pcs-xg100 firmware · CWE-306 | Высокая8,8 | — | 0,7 % | 9 июн. 2017 г. |
35Наблюдать | CVE-2020-5589Эксплойта нет | SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SPsony · wf-1000x firmware · CWE-306 | Высокая8,8 | — | 0,6 % | 9 июн. 2020 г. |
35Наблюдать | CVE-2025-5478Эксплойта нет | Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerabilitysony · xav-ax8500 firmware · CWE-190 | Высокая8,8 | — | 0,4 % | 20 июн. 2025 г. |
35Наблюдать | CVE-2025-5476Эксплойта нет | Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-653 | Высокая8,8 | — | 0,4 % | 20 июн. 2025 г. |
35Наблюдать | CVE-2025-5820Эксплойта нет | Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerabilitysony · xav-ax8500 firmware · CWE-288 | Высокая8,8 | — | 0,4 % | 20 июн. 2025 г. |
34Наблюдать | CVE-2012-2210Proof of concept | The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TCsony · bravia tv · CWE-399 | Высокая7,8 | — | 9,1 % | 11 апр. 2012 г. |
33Наблюдать | CVE-2019-11336Эксплойта нет | Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) bysony · photo sharing plus · CWE-532 | Высокая8,1 | — | 3,2 % | 14 мая 2019 г. |
32Наблюдать | CVE-2017-10909Эксплойта нет | Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan horsony · music center · CWE-426 | Высокая7,8 | — | 1,9 % | 22 дек. 2017 г. |
32Наблюдать | CVE-2018-16594Эксплойта нет | The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.sony · r5c firmware · CWE-22 | Высокая8,1 | — | 0,9 % | 19 июн. 2019 г. |
31Наблюдать | CVE-2018-3937Эксплойта нет | An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 fsony · snc-eb600 firmware · CWE-78 | Высокая7,2 | — | 9,6 % | 14 авг. 2018 г. |
31Наблюдать | CVE-2006-4235Эксплойта нет | Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to exesony · sonicstage mastering studio | Высокая7,5 | — | 5,0 % | 21 авг. 2006 г. |
31Наблюдать | CVE-2019-11890Эксплойта нет | Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wiredsony · bravia firmware · CWE-400 | Высокая7,5 | — | 4,4 % | 9 июл. 2019 г. |
- CVE-2007-348845В плане
Heap-based buffer overflow in the viewer ActiveX control in Sony Network Camera SNC-RZ25N before 1.30; SNC-P1 and SNC-P5 before 1.29; SNC-CS
КритическаяCVSS 10,0Proof of conceptEPSS 16 %sony · sony network camera snc-p529 июн. 2007 г.
- CVE-2008-074845В плане
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38
КритическаяCVSS 10,0Proof of conceptEPSS 16 %sony · axruploadserver activex control13 февр. 2008 г.
- CVE-2022-2374742В плане
In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed
КритическаяCVSS 9,8Эксплойта нетEPSS 10 %sony · xperia 1 firmware17 авг. 2022 г.
- CVE-2006-428942В плане
Buffer overflow in Sony VAIO Media Server 2.x, 3.x, 4.x, and 5.x before 20060626 allows remote attackers to execute arbitrary code via unspe
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %sony · vaio media server22 авг. 2006 г.
- CVE-2012-098541В плане
Multiple buffer overflows in the Wireless Manager ActiveX control 4.0.0.0 in WifiMan.dll in Sony VAIO PC Wireless LAN Wizard 1.0; VAIO Wirel
КритическаяCVSS 9,3Proof of conceptEPSS 13 %sony · smartwi connection utillity7 июн. 2012 г.
- CVE-2018-393841В плане
An exploitable stack-based buffer overflow vulnerability exists in the 802dot1xclientcert.cgi functionality of Sony IPELA E Series Camera G5
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %sony · snc-eb600 firmware14 авг. 2018 г.
- CVE-2007-570940В плане
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code via a long file nam
КритическаяCVSS 9,3Proof of conceptEPSS 11 %sony · sonicstage connect player30 окт. 2007 г.
- CVE-2019-1084439Наблюдать
nbla/logger.cpp in libnnabla.a in Sony Neural Network Libraries (aka nnabla) through v1.0.14 relies on the HOME environment variable, which
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %sony · neural network libraries4 апр. 2019 г.
- CVE-2020-3688537Наблюдать
Sony IPELA Network Camera 1.82.01 Remote Stack Buffer Overflow via ftpclient.cgi
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %sony · snc-dh120t firmware10 дек. 2025 г.
- CVE-2016-783436Наблюдать
SONY SNC-CH115, SNC-CH120, SNC-CH160, SNC-CH220, SNC-CH260, SNC-DH120, SNC-DH120T, SNC-DH160, SNC-DH220, SNC-DH220T, SNC-DH260, SNC-EB520, S
ВысокаяCVSS 8,8Proof of conceptEPSS 4 %sony · snc series firmware13 апр. 2017 г.
- CVE-2017-227736Наблюдать
WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage co
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %sony · wg-c10 firmware21 июл. 2017 г.
- CVE-2024-2393435Наблюдать
Sony XAV-AX5500 WMV/ASF Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sony · xav-ax550023 сент. 2024 г.
- CVE-2018-1659335Наблюдать
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Shell Metacharacter Injection.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sony · r5c firmware19 июн. 2019 г.
- CVE-2016-783035Наблюдать
Sony PCS-XG100, PCS-XG100S, PCS-XG100C, PCS-XG77, PCS-XG77S, PCS-XG77C devices with firmware versions prior to Ver.1.51 and PCS-XC1 devices
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sony · pcs-xg100 firmware9 июн. 2017 г.
- CVE-2020-558935Наблюдать
SONY Wireless Headphones WF-1000X, WF-SP700N, WH-1000XM2, WH-1000XM3, WH-CH700N, WH-H900N, WH-XB700, WH-XB900N, WI-1000X, WI-C600N and WI-SP
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %sony · wf-1000x firmware9 июн. 2020 г.
- CVE-2025-547835Наблюдать
Sony XAV-AX8500 Bluetooth SDP Protocol Integer Overflow Remote Code Execution Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sony · xav-ax8500 firmware20 июн. 2025 г.
- CVE-2025-547635Наблюдать
Sony XAV-AX8500 Bluetooth Improper Isolation Authentication Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sony · xav-ax8500 firmware20 июн. 2025 г.
- CVE-2025-582035Наблюдать
Sony XAV-AX8500 Bluetooth ERTM Channel Authentication Bypass Vulnerability
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %sony · xav-ax8500 firmware20 июн. 2025 г.
- CVE-2012-221034Наблюдать
The Sony Bravia TV KDL-32CX525 allows remote attackers to cause a denial of service (configuration outage or device crash) via a flood of TC
ВысокаяCVSS 7,8Proof of conceptEPSS 9 %sony · bravia tv11 апр. 2012 г.
- CVE-2019-1133633Наблюдать
Sony Bravia Smart TV devices allow remote attackers to retrieve the static Wi-Fi password (used when the TV is acting as an access point) by
ВысокаяCVSS 8,1Эксплойта нетEPSS 3 %sony · photo sharing plus14 мая 2019 г.
- CVE-2017-1090932Наблюдать
Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan hor
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %sony · music center22 дек. 2017 г.
- CVE-2018-1659432Наблюдать
The Photo Sharing Plus component on Sony Bravia TV through 8.587 devices allows Directory Traversal.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %sony · r5c firmware19 июн. 2019 г.
- CVE-2018-393731Наблюдать
An exploitable command injection vulnerability exists in the measurementBitrateExec functionality of Sony IPELA E Series Network Camera G5 f
ВысокаяCVSS 7,2Эксплойта нетEPSS 10 %sony · snc-eb600 firmware14 авг. 2018 г.
- CVE-2006-423531Наблюдать
Buffer overflow in the import project functionality in Sony SonicStage Mastering Studio 1.1.00 through 2.2.01 allows remote attackers to exe
ВысокаяCVSS 7,5Эксплойта нетEPSS 5 %sony · sonicstage mastering studio21 авг. 2006 г.
- CVE-2019-1189031Наблюдать
Sony Bravia Smart TV devices allow remote attackers to cause a denial of service (device hang or reboot) via a SYN flood attack over a wired
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %sony · bravia firmware9 июл. 2019 г.