Logitech kayıtları
logitech üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %2,7
- Pre-auth RCE
- 5
- Düzeltme kaydı olan
- %2,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-287 Improper Authentication2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-426 Untrusted Search Path2
- CWE-306 Missing Authentication for Critical Function1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
42Planlayın | CVE-2012-1250İstismar yok | Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminislogitech · lan-w300n\/ru2 firmware · CWE-264 | Kritik10,0 | — | %5,9 | 4 Haz 2012 |
40Planlayın | CVE-2008-0956İstismar yok | Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteInbackweb · backweb · CWE-119 | Kritik9,3 | — | %8,4 | 11 Haz 2008 |
40Planlayın | CVE-2018-15723İstismar yok | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.logitech · harmony hub firmware · CWE-346 | Kritik9,8 | — | %3,7 | 20 Ara 2018 |
40Planlayın | CVE-2018-15721İstismar yok | The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.logitech · harmony hub firmware · CWE-287 | Kritik9,8 | — | %1,8 | 20 Ara 2018 |
39İzleyin | CVE-2018-15720İstismar yok | Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the locallogitech · harmony hub firmware · CWE-798 | Kritik9,8 | — | %1,5 | 20 Ara 2018 |
39İzleyin | CVE-2024-2537İstismar yok | Electron Code Injection in Logi Tune macOS Applicationlogitech · logi tune · CWE-913 | Kritik9,8 | — | %0,3 | 15 Mar 2024 |
37İzleyin | CVE-2007-2918Silahlaştırılmış | Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Starlogitech · videocall | Orta6,8 | — | %34,1 | 31 May 2007 |
35İzleyin | CVE-2019-12506İstismar yok | Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone tlogitech · r700 laser presentation remote firmware · CWE-306 | Yüksek8,8 | — | %1,3 | 7 Haz 2019 |
35İzleyin | CVE-2022-0916İstismar yok | Broken authentication on Logitech Options due to misvalidation of Oauth state parameterlogitech · options · CWE-287 | Yüksek8,8 | — | %0,5 | 3 May 2022 |
32İzleyin | CVE-2018-15722İstismar yok | The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.logitech · harmony hub firmware · CWE-78 | Yüksek8,1 | — | %1,6 | 20 Ara 2018 |
31İzleyin | CVE-2001-0737İstismar yok | A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middlelogitech · cordless freedom | Yüksek7,5 | — | %1,7 | 18 Eki 2001 |
31İzleyin | CVE-2018-0620İstismar yok | Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan hologitech · game software · CWE-426 | Yüksek7,8 | — | %0,9 | 26 Tem 2018 |
31İzleyin | CVE-2018-0621İstismar yok | Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges vialogitech · connection utility software · CWE-426 | Yüksek7,8 | — | %0,9 | 26 Tem 2018 |
29İzleyin | CVE-2022-36263İstismar yok | StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.logitech · streamlabs desktop · CWE-284 | Yüksek7,3 | — | %0,4 | 19 Ağu 2022 |
28İzleyin | CVE-2022-0915İstismar yok | Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalationlogitech · sync · CWE-367 | Yüksek7,0 | — | %0,2 | 12 Nis 2022 |
27İzleyin | CVE-2021-20640İstismar yok | Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command logitech · lan-w300n\/pgrb firmware · CWE-120 | Orta6,8 | — | %0,6 | 12 Şub 2021 |
27İzleyin | CVE-2021-20638İstismar yok | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Orta6,8 | — | %0,5 | 12 Şub 2021 |
27İzleyin | CVE-2021-20639İstismar yok | LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.logitech · lan-w300n\/pgrb firmware · CWE-78 | Orta6,8 | — | %0,5 | 12 Şub 2021 |
26İzleyin | CVE-2019-13055İstismar yok | Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freqlogitech · unifying receiver firmware · CWE-200 | Orta6,5 | — | %1,0 | 29 Haz 2019 |
26İzleyin | CVE-2021-20642İstismar yok | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) conlogitech · lan-w300n\/rs firmware | Orta6,5 | — | %1,0 | 12 Şub 2021 |
26İzleyin | CVE-2021-20637İstismar yok | Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) clogitech · lan-w300n\/pr5b firmware | Orta6,5 | — | %1,0 | 12 Şub 2021 |
26İzleyin | CVE-2016-6257İstismar yok | The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60lenovo · ultraslim firmware · CWE-310 | Orta6,5 | — | %1,0 | 2 Ağu 2016 |
26İzleyin | CVE-2019-13054İstismar yok | The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.logitech · r500 firmware · CWE-522 | Orta6,5 | — | %0,8 | 29 Haz 2019 |
26İzleyin | CVE-2016-10761İstismar yok | Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.logitech · k400r firmware · CWE-74 | Orta6,5 | — | %0,7 | 29 Haz 2019 |
26İzleyin | CVE-2019-13052İstismar yok | Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.logitech · unifying receiver firmware · CWE-327 | Orta6,5 | — | %0,7 | 29 Haz 2019 |
- CVE-2012-125042Planlayın
Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain adminis
KritikCVSS 10,0İstismar yokEPSS %6logitech · lan-w300n\/ru2 firmware4 Haz 2012
- CVE-2008-095640Planlayın
Multiple stack-based buffer overflows in the BackWeb Lite Install Runner ActiveX control in the BackWeb Web Package ActiveX object in LiteIn
KritikCVSS 9,3İstismar yokEPSS %8backweb · backweb11 Haz 2008
- CVE-2018-1572340Planlayın
The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request.
KritikCVSS 9,8İstismar yokEPSS %4logitech · harmony hub firmware20 Ara 2018
- CVE-2018-1572140Planlayın
The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request.
KritikCVSS 9,8İstismar yokEPSS %2logitech · harmony hub firmware20 Ara 2018
- CVE-2018-1572039İzleyin
Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local
KritikCVSS 9,8İstismar yokEPSS %1logitech · harmony hub firmware20 Ara 2018
- CVE-2024-253739İzleyin
Electron Code Injection in Logi Tune macOS Application
KritikCVSS 9,8İstismar yokEPSS %0logitech · logi tune15 Mar 2024
- CVE-2007-291837İzleyin
Multiple stack-based buffer overflows in ActiveX controls (1) VibeC in (a) vibecontrol.dll, (2) CallManager and (3) ViewerClient in (b) Star
OrtaCVSS 6,8SilahlaştırılmışEPSS %34logitech · videocall31 May 2007
- CVE-2019-1250635İzleyin
Due to unencrypted and unauthenticated data communication, the wireless presenter Logitech R700 Laser Presentation Remote R-R0010 is prone t
YüksekCVSS 8,8İstismar yokEPSS %1logitech · r700 laser presentation remote firmware7 Haz 2019
- CVE-2022-091635İzleyin
Broken authentication on Logitech Options due to misvalidation of Oauth state parameter
YüksekCVSS 8,8İstismar yokEPSS %0logitech · options3 May 2022
- CVE-2018-1572232İzleyin
The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request.
YüksekCVSS 8,1İstismar yokEPSS %2logitech · harmony hub firmware20 Ara 2018
- CVE-2001-073731İzleyin
A long 'synch' delay in Logitech wireless mice and keyboard receivers allows a remote attacker to hijack connections via a man-in-the-middle
YüksekCVSS 7,5İstismar yokEPSS %2logitech · cordless freedom18 Eki 2001
- CVE-2018-062031İzleyin
Untrusted search path vulnerability in LOGICOOL Game Software versions before 8.87.116 allows an attacker to gain privileges via a Trojan ho
YüksekCVSS 7,8İstismar yokEPSS %1logitech · game software26 Tem 2018
- CVE-2018-062131İzleyin
Untrusted search path vulnerability in LOGICOOL CONNECTION UTILITY SOFTWARE versions before 2.30.9 allows an attacker to gain privileges via
YüksekCVSS 7,8İstismar yokEPSS %1logitech · connection utility software26 Tem 2018
- CVE-2022-3626329İzleyin
StreamLabs Desktop Application 1.9.0 is vulnerable to Incorrect Access Control via obs64.exe.
YüksekCVSS 7,3İstismar yokEPSS %0logitech · streamlabs desktop19 Ağu 2022
- CVE-2022-091528İzleyin
Logitech Sync desktop application prior to 2.4.574 - TOCTOU during installation leads to privelege escalation
YüksekCVSS 7,0İstismar yokEPSS %0logitech · sync12 Nis 2022
- CVE-2021-2064027İzleyin
Buffer overflow vulnerability in LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute an arbitrary OS command
OrtaCVSS 6,8İstismar yokEPSS %1logitech · lan-w300n\/pgrb firmware12 Şub 2021
- CVE-2021-2063827İzleyin
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
OrtaCVSS 6,8İstismar yokEPSS %0logitech · lan-w300n\/pgrb firmware12 Şub 2021
- CVE-2021-2063927İzleyin
LOGITEC LAN-W300N/PGRB allows an attacker with administrative privilege to execute arbitrary OS commands via unspecified vectors.
OrtaCVSS 6,8İstismar yokEPSS %0logitech · lan-w300n\/pgrb firmware12 Şub 2021
- CVE-2019-1305526İzleyin
Certain Logitech Unifying devices allow attackers to dump AES keys and addresses, leading to the capability of live decryption of Radio Freq
OrtaCVSS 6,5İstismar yokEPSS %1logitech · unifying receiver firmware29 Haz 2019
- CVE-2021-2064226İzleyin
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/RS allows a remote attacker to cause a denial-of-service (DoS) con
OrtaCVSS 6,5İstismar yokEPSS %1logitech · lan-w300n\/rs firmware12 Şub 2021
- CVE-2021-2063726İzleyin
Improper check or handling of exceptional conditions in LOGITEC LAN-W300N/PR5B allows a remote attacker to cause a denial-of-service (DoS) c
OrtaCVSS 6,5İstismar yokEPSS %1logitech · lan-w300n\/pr5b firmware12 Şub 2021
- CVE-2016-625726İzleyin
The firmware in Lenovo Ultraslim dongles, as used with Lenovo Liteon SK-8861, Ultraslim Wireless, and Silver Silk keyboards and Liteon ZTM60
OrtaCVSS 6,5İstismar yokEPSS %1lenovo · ultraslim firmware2 Ağu 2016
- CVE-2019-1305426İzleyin
The Logitech R500 presentation clicker allows attackers to determine the AES key, leading to keystroke injection.
OrtaCVSS 6,5İstismar yokEPSS %1logitech · r500 firmware29 Haz 2019
- CVE-2016-1076126İzleyin
Logitech Unifying devices before 2016-02-26 allow keystroke injection, bypassing encryption, aka MouseJack.
OrtaCVSS 6,5İstismar yokEPSS %1logitech · k400r firmware29 Haz 2019
- CVE-2019-1305226İzleyin
Logitech Unifying devices allow live decryption if the pairing of a keyboard to a receiver is sniffed.
OrtaCVSS 6,5İstismar yokEPSS %1logitech · unifying receiver firmware29 Haz 2019