İçeriğe atla
Noroxi

Logitech kayıtları

logitech üreticisine ait 37 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
1 · %2,7
Pre-auth RCE
5
Düzeltme kaydı olan
%2,7
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Bug bounty kapsamı

Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.

Tüm kayıtlar

37 kayıt
  • CVE-2012-1250
    42Planlayın

    Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminis

    KritikCVSS 10,0İstismar yokEPSS %6

    logitech · lan-w300n\/ru2 firmware4 Haz 2012

  • CVE-2008-0956
    40Planlayın

    Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteIn

    KritikCVSS 9,3İstismar yokEPSS %8

    backweb · backweb11 Haz 2008

  • CVE-2018-15723
    40Planlayın

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.

    KritikCVSS 9,8İstismar yokEPSS %4

    logitech · harmony hub firmware20 Ara 2018

  • CVE-2018-15721
    40Planlayın

    The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.

    KritikCVSS 9,8İstismar yokEPSS %2

    logitech · harmony hub firmware20 Ara 2018

  • CVE-2018-15720
    39İzleyin

    Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local

    KritikCVSS 9,8İstismar yokEPSS %1

    logitech · harmony hub firmware20 Ara 2018

  • CVE-2024-2537
    39İzleyin

    Electron Code Injection in Logi Tune macOS Application

    KritikCVSS 9,8İstismar yokEPSS %0

    logitech · logi tune15 Mar 2024

  • CVE-2007-2918
    37İzleyin

    Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Star

    OrtaCVSS 6,8SilahlaştırılmışEPSS %34

    logitech · videocall31 May 2007

  • CVE-2019-12506
    35İzleyin

    Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone t

    YüksekCVSS 8,8İstismar yokEPSS %1

    logitech · r700 laser presentation remote firmware7 Haz 2019

  • CVE-2022-0916
    35İzleyin

    Broken authentication on Logitech Options due to misvalidation of Oauth state parameter

    YüksekCVSS 8,8İstismar yokEPSS %0

    logitech · options3 May 2022

  • CVE-2018-15722
    32İzleyin

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.

    YüksekCVSS 8,1İstismar yokEPSS %2

    logitech · harmony hub firmware20 Ara 2018

  • CVE-2001-0737
    31İzleyin

    A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle

    YüksekCVSS 7,5İstismar yokEPSS %2

    logitech · cordless freedom18 Eki 2001

  • CVE-2018-0620
    31İzleyin

    Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan ho

    YüksekCVSS 7,8İstismar yokEPSS %1

    logitech · game software26 Tem 2018

  • CVE-2018-0621
    31İzleyin

    Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via

    YüksekCVSS 7,8İstismar yokEPSS %1

    logitech · connection utility software26 Tem 2018

  • CVE-2022-36263
    29İzleyin

    StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.

    YüksekCVSS 7,3İstismar yokEPSS %0

    logitech · streamlabs desktop19 Ağu 2022

  • CVE-2022-0915
    28İzleyin

    Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation

    YüksekCVSS 7,0İstismar yokEPSS %0

    logitech · sync12 Nis 2022

  • CVE-2021-20640
    27İzleyin

    Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command

    OrtaCVSS 6,8İstismar yokEPSS %1

    logitech · lan-w300n\/pgrb firmware12 Şub 2021

  • CVE-2021-20638
    27İzleyin

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    OrtaCVSS 6,8İstismar yokEPSS %0

    logitech · lan-w300n\/pgrb firmware12 Şub 2021

  • CVE-2021-20639
    27İzleyin

    LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.

    OrtaCVSS 6,8İstismar yokEPSS %0

    logitech · lan-w300n\/pgrb firmware12 Şub 2021

  • CVE-2019-13055
    26İzleyin

    Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freq

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · unifying receiver firmware29 Haz 2019

  • CVE-2021-20642
    26İzleyin

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) con

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · lan-w300n\/rs firmware12 Şub 2021

  • CVE-2021-20637
    26İzleyin

    Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) c

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · lan-w300n\/pr5b firmware12 Şub 2021

  • CVE-2016-6257
    26İzleyin

    The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60

    OrtaCVSS 6,5İstismar yokEPSS %1

    lenovo · ultraslim firmware2 Ağu 2016

  • CVE-2019-13054
    26İzleyin

    The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · r500 firmware29 Haz 2019

  • CVE-2016-10761
    26İzleyin

    Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · k400r firmware29 Haz 2019

  • CVE-2019-13052
    26İzleyin

    Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.

    OrtaCVSS 6,5İstismar yokEPSS %1

    logitech · unifying receiver firmware29 Haz 2019